Cisco Patches SD-WAN Manager Flaw That Lets Attackers Bypass Login

Cisco patches an actively exploited SD-WAN Manager flaw that lets attackers bypass login. Learn which releases fix it and what logs defenders should check.

Oct 5, 2026
2 minute read
Cisco logo.

Cisco discloses SD-WAN zero-day exploited in the wild. Image generated via ChatGPT.

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Cisco’s SD-WAN management layer has become the latest target for attackers exploiting a zero-day that can hand them administrator access without a password.

Cisco issued an urgent advisory warning that attackers are actively exploiting a critical authentication bypass in Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. Tracked as CVE-2026-76504, the flaw carries a near-maximum CVSS severity score of 9.8.

The vendor discovered the activity while resolving a Technical Assistance Center support ticket. The Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog Sept. 30, with an Oct. 3 remediation deadline for Federal Civilian Executive Branch agencies.

Anatomy of an API bypass

The flaw stems from how the central management platform handles URI encoding during API session-based authentication. An unauthenticated remote attacker can bypass access controls by transmitting a specially crafted HTTP request to an exposed system.

"An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user," Cisco said.

According to technical indicators released by the company, adversaries have substituted characters with URL encodings, such as using "%6a" in place of "j" to call the j_security_check endpoint and abuse internal service accounts.

Why this matters for network defenders

SD-WAN Manager centralizes network administration, making unauthorized administrative access a serious concern. Compromise could expose network configurations or enable unauthorized changes, although Cisco has not detailed what attackers did after exploiting this flaw.

The practical takeaway is to patch affected systems, restrict management access, and investigate suspicious activity. Patching should accompany a compromise assessment.

Advertisement

What network teams must do

Cisco lists no workaround that fixes the vulnerability. Administrators should upgrade to the fixed release for their software branch: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Cisco SD-WAN Cloud (Cisco Managed) release 20.15.605 addresses the flaw and requires no customer action. On-premises teams should also take these steps:

  • Inspect core access logs: Audit serviceproxy-access.log and vmanage-server.log for encoded requests to j_security_check originating from unauthorized IPs or targeting viptela-reserved accounts.
  • Isolate interfaces: Pull management portals off the public internet, placing them strictly behind firewalls or dedicated administrative segments.
  • Investigate suspected compromise: Generate an admin-tech archive using the request admin-tech command and open a Severity 3 Cisco TAC case with CVE-2026-76504 in the title for review.

Read more: For context on earlier attacks against the same platform, read how separate Cisco SD-WAN Manager vulnerabilities were exploited to overwrite files and expose sensitive information.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.