CISCO has identified and patched a critical authentication bypass in Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-76504. The flaw, rated CVSS 9.8, lies in the API session-based authentication logic and stems from improper handling of URI encoding in an HTTP request. Exploitation has been observed in the wild, with attackers able to achieve unauthenticated admin access to the SD-WAN Manager API.
Cisco notes that the compromise requires no user interaction or credentials, and a crafted request can bypass the guard on a specific API endpoint. The exposure is particularly serious because SD-WAN Manager can control large fabric deployments; reports suggest a single instance can manage thousands of devices, giving attackers potential reach across branches.
Affected software includes Cisco SD-WAN Manager releases across multiple lines, including 18.3.6, 18.3.7, 18.3.8, 17.2.10, 18.3.6[.]1, 18.2.0, and additional variants (listed as “+17 more”). Cisco has published fixed releases, with guidance to migrate to the earliest fixed version: 20.9.10[.]1 (for 20.9 line), 20.12.8[.]2 (20.12), 20.15.6[.]1 (20.15), 20.18.4[.]1 (20.18), 26.1.2[.]1 (26.1), and 26.2.1 (26.2). Cisco’s managed cloud service was fixed in Release 20.15.605.
In the meantime, Cisco recommends upgrading as the primary mitigation and, for on‑prem deployments, blocking internet access to the Manager to limit exposure. Administrators should hunt for signs of compromise in log files (serviceproxy-access[.]log and vmanage-server[.]log) and look for j_security_check requests from unknown IPs, or accounts starting with viptela-reserved-.
Before upgrading, administrators are advised to run request admin-tech to preserve evidence and to open a Severity 3 TAC case if suspicious activity is detected.