CISA confirms active exploitation of the critical Cisco Catalyst SD-WAN Manager flaw (CVE-2026-76504)
CISA has added the critical authentication bypass in the Cisco Catalyst SD-WAN Manager API to its KEV catalog, with a federal remediation deadline of 3 October 2026. Any organisation running this platform, especially if internet-facing, should patch immediately and hunt for indicators of compromise.
What happened
This is a follow-up to the Cisco Catalyst SD-WAN Manager vulnerability published earlier today, 30 September 2026. What is new is that CISA has added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog, meaning real-world exploitation has been confirmed. US federal agencies have until 3 October 2026 to remediate, a very short window that reflects the urgency of the case.
The flaw carries a CVSS score of 9.8 (critical) and allows an unauthenticated, remote attacker to access the system with the privileges of the admin user. According to Cisco's advisory, the root cause is improper handling of URI encoding in HTTP requests, which lets a request bypass the authentication rule protecting a specific API endpoint.
Who is affected
Cisco's advisory states that the vulnerability affects Cisco Catalyst SD-WAN Manager (vManage) regardless of system configuration. The highest risk is for on-premises deployments with ports reachable from the internet. For Cisco Catalyst SD-WAN Cloud Hosted environments, the vendor says the mitigation has already been deployed.
The details come from the vendor advisory (Cisco PSIRT); NVD has not published the CVE record yet. There is no EPSS score for this flaw, but with it now in KEV the theoretical probability is beside the point: exploitation is already happening.
What to do
There are no workarounds that fix the issue: the only remediation is upgrading to a fixed software release, as Cisco states in the Fixed Software section of its advisory. Beyond patching, any exposed system should be treated as potentially compromised and checked for evidence of attack.
- Upgrade Cisco Catalyst SD-WAN Manager to the fixed release indicated by Cisco, without waiting for the usual maintenance window.
- Check whether the management console is reachable from the internet and, while patching, restrict access to known, trusted hosts only, behind a filtering device such as a firewall, following the Cisco hardening guide.
- Review /var/log/nms/containers/service-proxy/serviceproxy-access.log for requests to j_security_check containing URI-encoded characters (for example %6a_security_check) from unknown IP addresses.
- Review /var/log/nms/vmanage-server.log for j_security_check calls associated with usernames starting with viptela-reserved-.
- If there are signs of compromise, run request admin-tech on vManage and open a Cisco TAC case as Severity 3 with CVE-2026-76504 in the title.
- Rotate administrative credentials and review recent configuration changes and newly created accounts.
Context
Cisco warns that some of these indicators can also appear during standard operations, so they should be assessed against your normal network posture to avoid false positives. The %6a example is illustrative only: any single encoded character in the request can be used to exploit the flaw.
SD-WAN management platforms control an entire distributed network, so admin-level access can translate into control over many branch sites. That is precisely why systems of this kind should never be published directly on the internet.
Affected technologies
Vulnerabilities (1)
| CVE | Severity | Active exploitation | Published | NVD status |
|---|---|---|---|---|
| CVE-2026-76504 | Critical (9.8) | ⚠ Active exploitation | 9/30/2026 | Analyzed |
Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.