CyberSecurityNews

Cisco SD-WAN Manager Authentication 0-day Vulnerability Actively Exploited in the Wild


Cisco has disclosed a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager that attackers are actively exploiting.

The flaw, tracked as CVE-2026-76504, could allow an unauthenticated remote attacker to gain administrative access to vulnerable SD-WAN management systems. The vulnerability received a CVSS score of 9.8 and affects Cisco Catalyst SD-WAN Manager regardless of its system configuration.

CVE-2026-76504 exists in the API session-based authentication management component of Cisco Catalyst SD-WAN Manager. The issue results from improper handling of URI encoding in HTTP requests.

An attacker can send a specially crafted request to the exposed API and bypass an authentication rule intended to protect a specific endpoint.

Successful exploitation allows the attacker to access the API with administrator-level privileges. This could give an intruder control over a high-value SD-WAN management platform, potentially enabling network configuration changes, access to connected infrastructure, and further compromise of enterprise environments.

Cisco SD-WAN Manager 0-Day Vulnerability Exploited

Cisco said attackers can abuse encoded characters in requests to the j_security_check endpoint. The company provided an example involving the encoded character %6a, which represents the letter “j”: POST /%6a_security_check HTTP/1.1

Cisco noted that %6a is only one example. Any single character encoded in the request could potentially trigger the authentication bypass.

Administrators should immediately investigate Cisco Catalyst SD-WAN Manager logs for suspicious access attempts. Cisco specifically recommends reviewing the serviceproxy-access.log file at /var/log/nms/containers/service-proxy/serviceproxy-access.log for requests involving j_security_check from unfamiliar or unauthorized IP addresses.

Security teams should also inspect /var/log/nms/vmanage-server.log for requests to encoded j_security_check paths associated with usernames beginning with viptela-reserved-. These are system service accounts, and suspicious requests involving such accounts may indicate attempted or successful exploitation.

No workarounds fully address the flaw. For on-premises deployments, Cisco recommends restricting SD-WAN Manager access from the public internet, permitting access only from known and trusted hosts, and placing SD-WAN control components behind filtering devices such as firewalls.

Cisco published the advisory( cisco-sa-sdwan-webauth-xr8beuuU ) on September 30, 2026. The company confirmed it became aware of active exploitation in September and strongly urged organizations to apply software updates.

Cisco SD-WAN Cloud Hosted environments already have this mitigation deployed. Organizations should upgrade to fixed releases as soon as possible. Cisco has released patches in versions 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1.

Cisco SD-WAN Cloud Managed Release 20.15.605 also fixes the issue, with no customer action required. Cisco customers who suspect compromise should collect an admin-tech file using the request admin-tech command and open a Severity 3 TAC case referencing CVE-2026-76504.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link