Cisco SD-WAN Manager CVE-2026-76504 exploited: no workaround
Cisco SD-WAN Manager CVE-2026-76504 lets an attacker with no login use the API as admin. It is exploited, and no workaround exists. Upgrade and check the logs.
If your stores, clinics, or offices share one network through Cisco SD-WAN, one server controls all of them: the SD-WAN Manager. On September 30, Cisco disclosed Cisco SD-WAN Manager CVE-2026-76504, a critical authentication bypass with a CVSS score of 9.8. Attackers already use it. There is no workaround. The fix is an upgrade, then a look at the logs to see if someone got in before you patched.
What actually happened
Per Cisco's advisory, the Manager handles URI encoding in an HTTP request incorrectly. A crafted request gets around an authentication rule on one API endpoint. The result: an attacker with no credentials can use that API as the admin user. The attacker only needs to reach the Manager's API over the network.
Cisco says its incident response team became aware of active exploitation in September 2026. The Hacker News reports that Cisco found the flaw while it worked on a support case.
Fixed releases:
- 20.9 → 20.9.10.1
- 20.12 → 20.12.8.2
- 20.15 → 20.15.6.1
- 20.18 → 20.18.4.1
- 26.1 → 26.1.2.1
- 26.2 → 26.2.1
- Earlier than 20.9 → migrate to a fixed release
Cisco says cloud-hosted customers got the fix automatically in release 20.15.605. Cisco offers a temporary "Live Protect" shield, but it warns that the shield can block legitimate logins that use URI encoding.
Why it matters for your business
The Manager is the keys to every site. SD-WAN centralizes policy for all of your locations. Admin access to the Manager is admin access to the network design of the whole business, not to one router.
"No workaround" means the clock is real. You cannot turn off a feature and wait. If your managed service provider runs the Manager for you, ask them today which release you are on and when they upgraded.
Patching does not tell you if you were already breached. Cisco lists what to look for: requests that contain %6a_security_check (a URI-encoded "j") in /var/log/nms/containers/service-proxy/serviceproxy-access.log, and vmanage-server.log entries for viptela-reserved- accounts from sources you do not know. Check before you call this closed.
The management interface should never face the internet. Cisco's main mitigation advice is to restrict access to the Manager and filter it behind a firewall. That is good practice for every admin console you own.
Key takeaways
- CVE-2026-76504 (CVSS 9.8) lets an unauthenticated attacker use the SD-WAN Manager API as admin
- Cisco confirms active exploitation; there is no workaround
- Upgrade to the fixed release for your train (for example, 20.15.6.1 or 26.2.1)
- Search the service-proxy and vmanage-server logs for the indicators Cisco lists
- Put the Manager API behind a firewall, away from untrusted networks
Not sure who patches the box that runs your network? We map every admin console, appliance, and self-hosted tool in a business, name an owner for each, and set up the update plan. See what we build, or ask us to check your stack.
Sources: Cisco security advisory cisco-sa-sdwan-webauth-xr8beuuU, The Hacker News.
- #cisco
- #cve-2026-76504
- #sd-wan
- #patch-management
- #network-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Warlock ransomware rides year-old SharePoint ToolShell bugs
Symantec says Warlock ransomware used 2025 SharePoint ToolShell flaws, a VS Code tunnel, and SYSVOL to hit 33+ hosts in two hours. Patch and rotate keys.
Read itSchneider Electric buys PTC for $22.6B: check your CAD renewal
Schneider Electric will buy PTC, maker of Onshape, Creo, and Windchill, for $22.6B. Nothing changes until 2027. Use the time to secure your CAD data and terms.
Read it