Cisco SD-WAN Manager zero-day CVE-2026-76504 exploited

Cisco SD-WAN Manager zero-day CVE-2026-76504 exploited

Cisco has released security updates for a critical zero-day in Catalyst SD-WAN Manager that attackers are already using to gain administrator privileges on vulnerable systems. The flaw is tracked as CVE-2026-76504.

Catalyst SD-WAN Manager was previously called SD-WAN vManage. It is network management software that lets administrators monitor and control up to 6,000 SD-WAN devices from one dashboard. A compromise of this platform could therefore give an attacker a central view of, and potential control over, a large part of an organization's wide area network.

"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company said on Wednesday. PSIRT is Cisco's Product Security Incident Response Team, the group that handles vulnerability reports for the vendor's products. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."

An encoding trick that skips authentication

The bug sits in the API session-based authentication management of the software. According to Cisco, every deployment is affected, whatever the system configuration. A remote attacker does not need credentials to exploit it and can end up with admin-level access.

"This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint," Cisco explained.

In practice, exploitation requires only a specially crafted HTTP request sent to the API of the affected system. The authentication rule that should block access to a particular endpoint fails to recognize the request because of how its URI is encoded.

Cisco did not describe the attacks it has observed or say who is behind them. It did, however, publish indicators of compromise (IOCs). According to the advisory, malicious requests use %6a, the URI-encoded form of the letter "j".

Where to look for signs of compromise

Security teams that suspect an SD-WAN Manager instance may have been breached should review two log files:

  • serviceproxy-access.log, located under /var/log/nms/containers/service-proxy
  • vmanage-server.log, located under /var/log/nms/

In both files, analysts should look for entries related to j_security_check that originate from unknown or unauthorized IP addresses.

Customers who need help working out whether a system has been compromised can open a case with the Cisco TAC, the vendor's Technical Assistance Center. Cisco advises administrators to collect admin-tech files first, so the support team has the data it needs for the review.

A difficult year for Cisco SD-WAN

CVE-2026-76504 is the fifth SD-WAN zero-day exploited in the wild since January.

In February, Cisco fixed an information disclosure flaw in SD-WAN Manager (CVE-2026-20127) that had been exploited since at least 2023. In May, the company flagged a maximum-severity authentication bypass in Catalyst SD-WAN Controller (CVE-2026-20182) as actively exploited in zero-day attacks to obtain admin privileges on unpatched devices.

Early June brought two more SD-WAN zero-days, CVE-2026-20245 and CVE-2026-20262, which attackers used to gain root privileges on vulnerable systems.

The wider picture is not much better. Since November 2021, the US Cybersecurity and Infrastructure Security Agency (CISA) has added 90 Cisco vulnerabilities to its list of flaws exploited in the wild. Four of them affect Cisco Catalyst SD-WAN Manager, and seven have been abused in ransomware operations.

Our take

The core problem here is not new. A single encoded character is enough to slip past an authentication rule, and the target is a management console that can oversee thousands of network devices. For attackers, that combination of low effort and high reward is hard to ignore. The fact that all deployments are affected, regardless of configuration, removes the usual "maybe our setup is safe" comfort that some admins rely on.

The pattern across 2026 is also worth noting. Five exploited zero-days in one product line within nine months suggests that Cisco's SD-WAN platform has become a sustained focus for threat actors, not an occasional target. It fits a broader trend of attackers going after edge and network management appliances, as seen this month with the Citrix NetScaler auth bypass under mass attack and the exploited Check Point VPN flaw. Similar concerns apply to routing gear such as MikroTik RouterOS. These systems sit at the heart of networks, are often reachable from outside, and rarely run endpoint security tools.

For readers running Catalyst SD-WAN Manager, patching should come first, but it is not the whole job. Because exploitation was already under way before the fix, checking the logs Cisco listed for the IOCs is a sensible step, even on systems that are now updated. Limiting exposure of the management interface to trusted networks may also reduce risk from the next bug in this product family.

It is worth watching whether CISA adds CVE-2026-76504 to its catalog of exploited vulnerabilities, and whether Cisco or other researchers later tie the attacks to a known group. Given that earlier Cisco flaws have been used by ransomware gangs, how this one is used next will say a lot about the risk for organizations that are slow to update.