securityaffairs.com 1 Oct 2026, 08:35 UTC

CISA Flags Actively Exploited Cisco SD-WAN Authentication Flaw

CISA Flags Actively Exploited Cisco SD-WAN Authentication Flaw
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Cisco Catalyst SD-WAN Manager’s flaw to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is tracked as CVE-2026-76504 and carries a CVSS score of 9.8. It affects Cisco Catalyst SD-WAN Manager software and resides in the session authentication mechanism, allowing a remote attacker with no credentials to access the system with administrator-level privileges.

Cisco’s advisory states the flaw arises from improper handling of URI encoding in an HTTP request, which lets an attacker bypass an authentication rule intended to protect a specific API endpoint. Successful exploitation could grant authentication bypass and admin-level access to the API. Cisco reports that active exploitation was observed from September 2026, with the issue discovered during a customer support investigation by its TAC.

Mitigations and indicators of compromise are provided by Cisco. There is no workaround for the vulnerability. For on‑premises deployments, organisations are advised to restrict internet access and place SD‑WAN control components behind a firewall, allowing traffic only from trusted hosts; mitigations are already in place for cloud‑hosted environments, but customers should assess the impact before deployment.

Affected Software Release versions and fixed releases are listed (ranging from versions earlier than 20.9 through 26.2). Organisations are urged to upgrade to fixed releases and check for signs of compromise, including reviewing serviceproxy-access[.]log for j_security_check requests from unknown IPs and vmanage-server[.]log for usernames beginning with viptela-reserved-.

Cisco recommends generating an admin-tech file via the vManage command for TAC analysis and filing Severity 3 cases with CVE-2026-76504 in the title if compromise is suspected. Agencies are reminded of the due dates under Binding Operational Directive 22-01.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline