Cisco has released fixed software for a critical Cisco Catalyst SD-WAN Manager authentication bypass after becoming aware of active exploitation in September 2026, according to its Sept. 30 security advisory.
The vulnerability, tracked as CVE-2026-76504, carries a CVSS 3.1 base score of 9.8 and affects Cisco Catalyst SD-WAN Manager regardless of system configuration. The disclosure has the practical profile of a zero-day: Cisco reported exploitation in the same advisory that introduced fixed releases.
The bug sits in API session-based authentication. Cisco says improper handling of URI encoding can let an unauthenticated remote attacker use a crafted HTTP request to bypass an authentication rule for a protected API endpoint. A successful exploit could give the attacker access to the API as the admin user.
The operational concern is the role of SD-WAN Manager itself. It is not a typical workstation or single application server; it is part of the management layer used to administer SD-WAN environments. Admin API access in that layer can expose configuration and control functions that sit close to core network operations.
No workaround, but access restrictions still matter
Cisco says no workaround addresses CVE-2026-76504. For on-premises deployments, it recommends restricting access from unsecured networks such as the internet. If internet access is required, Cisco says access should be limited to known, trusted hosts and the SD-WAN control components should sit behind a filtering device such as a firewall.
Cisco also cautions that any mitigation can affect network functionality or performance and should be evaluated in the deployment where it is used. The mitigation reduces exposure; it does not replace fixed software.
Fixed Cisco SD-WAN releases
Cisco lists the following first fixed releases for Catalyst SD-WAN Software. Systems running earlier releases need to move to a fixed release supported by the deployment. Internet-facing Manager instances deserve priority because Cisco identifies exposed systems with internet-facing ports as at risk of compromise.
| Cisco Catalyst SD-WAN Software release | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Cisco says Cisco SD-WAN Cloud, Cisco Managed, is addressed in cloud-based release 20.15.605 and that no user action is required.
Compromise review is part of the response
Because Cisco has confirmed active exploitation, patching alone does not answer whether a vulnerable Manager was already reached. Cisco’s indicator guidance points administrators to serviceproxy-access.log and vmanage-server.log, where they should review j_security_check activity from unknown or unauthorized IP addresses and activity involving viptela-reserved service account names.
Cisco warns that some of these indicators can appear during standard operations, so the entries need to be checked against normal network posture before being treated as proof of compromise. Customers that need help assessing exposure can open a Severity 3 Cisco TAC case with CVE-2026-76504 in the title and provide an admin-tech file collected from SD-WAN Manager.
Canadian and U.S. agencies flagged it quickly
The Canadian Centre for Cyber Security’s Oct. 1 alert listed Cisco Catalyst SD-WAN Manager versions prior to the fixed releases as affected and encouraged administrators to review Cisco’s guidance and apply updates as available. The alert also noted that the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-76504 to its Known Exploited Vulnerabilities catalogue on Sept. 30.
A recurring SD-WAN exposure theme
Rapid7 noted that Catalyst SD-WAN Manager and related control components were also affected by critical unauthenticated peering-authentication flaws earlier in 2026, including CVE-2026-20127 and CVE-2026-20182. Rapid7 says CVE-2026-76504 targets a separate API authentication path rather than the earlier vdaemon path.
That distinction matters for operators reviewing older SD-WAN patch work. Fixing previous SD-WAN authentication bypasses does not prove this API issue is closed; the Manager release still needs to be checked against Cisco’s Sept. 30 fixed-release table.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







