CVE-2026-76504: Cisco SD-WAN Manager Zero-Day Exploited in Wild

CVE-2026-76504: Cisco SD-WAN Manager Zero-Day Exploited in Wild


Executive Summary

Cisco Catalyst SD-WAN Manager is dealing with a serious zero-day that is already being exploited in the wild.

Tracked as CVE-2026-76504, the flaw allows an unauthenticated attacker to bypass the authentication mechanism and gain administrator-level access to the SD-WAN management API. Since SD-WAN Manager sits at the centre of the network management plane, this is not a vulnerability that should wait for the next routine patch cycle.

What is happening?

The issue comes from the way SD-WAN Manager handles URI encoding.

An attacker can send a specially crafted request using URL encoding to get around the authentication check. The application then processes the request even though the attacker has not provided valid credentials.

In simple terms, the attacker can find a way around the front door without having the key.

Why this matters

The concern is not just gaining access to one application.

SD-WAN Manager is used to manage the wider SD-WAN environment. If an attacker gains administrative API access, they could potentially make changes that affect the network infrastructure managed through the platform.

That makes the management plane the real concern here.

What should security teams look for?

Cisco recommends checking the SD-WAN Manager logs for unusual activity, including:

  • serviceproxy-access.log
  • vmanage-server.log
  • Suspicious requests involving j_security_check
  • URL-encoded variations of authentication requests
  • Connections from unfamiliar or unauthorized IP addresses
  • Unexpected activity involving viptela-reserved- accounts

If anything suspicious is found, correlate it with administrative activity around the same time. The objective is to establish whether the system was simply probed or actually compromised.

Patch immediately

Cisco has released fixes for supported versions:

20.9 → 20.9.10.1
20.12 → 20.12.8.2
20.15 → 20.15.6.1
20.18 → 20.18.4.1
26.1 → 26.1.2.1
26.2 → 26.2.1

There is no workaround, according to Cisco.

Until the upgrade is completed, access to SD-WAN Manager should be limited to trusted sources wherever possible.

The takeaway

CVE-2026-76504 is a good reminder that sometimes a very small application flaw can have a much bigger security consequence.

Here, a URL-encoding issue has become an authentication bypass against a centralized network management platform.

For security teams, the response should therefore be straightforward:

Patch it. Hunt for exploitation. Check what happened before the patch.

Because with an actively exploited zero-day, knowing that the vulnerability is fixed is only half the story.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.