ITnews

Cisco says no workaround for exploited SD-WAN Manager flaw


Key points

  • Cisco warns attackers are actively exploiting a critical authentication bypass, tracked as CVE-2026-76504 with a CVSS score of 9.8, in its Catalyst SD-WAN Manager software.
  • The flaw lets an unauthenticated attacker reach the Manager’s API as the admin user via a specially crafted HTTP request exploiting improper URI encoding handling.
  • No workarounds exist, so Cisco strongly recommends upgrading to fixed releases, with customers on anything earlier than 20.9 required to migrate.



Networking giant Cisco said attackers are exploiting a critical authentication bypass in its Catalyst SD-WAN Manager software, formerly known as vManage.

The company said its Product Security Incident Response Team (PSIRT) became aware of active exploitation in September.

Tracked as CVE-2026-76504, the flaw carries a common vulnerabilities scoring system (CVSS) rating of 9.8 out of 10.0.

It lets an unauthenticated attacker reach the Manager’s application programming interface (API) as the admin user by sending a specially crafted HTTP request.

The cause is improper handling of uniform resource identifier (URI) encoding, and the flaw allows a request to slip past an authentication rule meant to protect a specific API endpoint.

Cisco’s example in the advisory uses the %6a string in place of the letter j, but the company said any single encoded character will do.

That makes a search for one literal string a weak test on its own and admins are advised to audit the serviceproxy-access.log and vmanage-server.log files, searching for j_security_check entries from unknown, or unauthorised addresses in the former, and requests involving users whose names start with “viptela-reserved-“.

Cisco said the flaw affects SD-WAN Manager “regardless of system configuration.”

It lists no workarounds but the advisory suggests on-premises customers keep the system away from unsecured networks, such as the internet, as a mitigation.

Where internet access is required, the company said, access should be limited to known, trusted hosts, with the control components behind a firewall.

Cisco said it strongly recommends upgrading, and that any mitigation is a stopgap until a fixed release is installed.

Fixed releases start at 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, depending on the release train.

Customers running anything earlier than 20.9 must migrate to a fixed release.

If customers suspect a compromise, they can open a Severity 3 case with Cisco’s Technical Assistance Center (TAC), with the CVE in the title, after running the request admin-tech command.

The company did not say who is exploiting the flaw, how many customers are affected, or when attacks began beyond September.

Cisco said the bug was found while resolving a support case.

The flaw is separate from CVE-2026-20182, fixed in May, and CVE-2026-20245 and CVE-2026-20262, fixed in June.



Source link