Cisco patches a critical Catalyst SD-WAN Manager flaw that grants admin access without credentials
Cisco has issued an advisory for CVE-2026-76504, a critical flaw (CVSS 9.8) in the Catalyst SD-WAN Manager API that lets an unauthenticated remote attacker access the system with administrator privileges. A software update is available, but there is no workaround.
What happened
On 30 September 2026 Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU, describing an API authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage). The issue, tracked as CVE-2026-76504, carries a CVSS base score of 9.8, placing it in the critical range.
According to the Cisco advisory, the root cause lies in the API's session-based authentication management: the system mishandles URI encoding in HTTP requests, allowing a request to bypass the authentication rule that protects a specific API endpoint. Sending a single crafted HTTP request is enough to gain API access as the admin user, with no credentials and no user interaction required.
The details come from the vendor advisory; NVD has not published the entry yet.
Who is affected
Cisco states that the vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration. The advisory's Fixed Software section is the reference for which releases are vulnerable and which ones to upgrade to.
Exposure is highest for on-premises deployments reachable from the internet. For Cisco Catalyst SD-WAN Cloud Hosted environments, the access-restriction mitigation has already been deployed by Cisco.
Exploitation status
The vulnerability is not listed in CISA's KEV catalogue and has no EPSS score yet, so there is no public evidence of active exploitation. Even so, Cisco has published indicators of compromise in the advisory, which is unusual and a good reason to treat this as a high-priority case.
What to do
Cisco warns that there are no workarounds that fix the flaw: upgrading to a fixed release is the only remediation. Recommended steps:
- Upgrade Catalyst SD-WAN Manager to one of the fixed releases listed in the Fixed Software section of the Cisco advisory.
- Until the upgrade is done, restrict access to the system from untrusted networks such as the internet, allow traffic only from known, trusted hosts on documented ports and protocols, and keep SD-WAN control components behind a filtering device such as a firewall (see the Cisco Catalyst SD-WAN Hardening Guide).
- Audit /var/log/nms/containers/service-proxy/serviceproxy-access.log for j_security_check entries from unknown or unauthorised IP addresses containing URI-encoded characters (for example, POST /%6a_security_check).
- Audit /var/log/nms/vmanage-server.log for j_security_check calls involving user names beginning with viptela-reserved-.
- If compromise is suspected, generate the admin-tech file with the request admin-tech command and open a Severity 3 case with Cisco TAC, including CVE-2026-76504 in the title.
- Bear in mind that these indicators can also appear during normal operations, so compare them against your usual network activity to rule out false positives.
Affected technologies
Vulnerabilities (1)
| CVE | Severity | Active exploitation | Published | NVD status |
|---|---|---|---|---|
| CVE-2026-76504 | Critical (9.8) | ⚠ Active exploitation | 9/30/2026 | Analyzed |
Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.