Skip to content
Rush Commerce
Software & Dev3 min read

Cisco SD-WAN Manager CVE-2026-76504 exploited: no workaround

Cisco SD-WAN Manager CVE-2026-76504 lets an attacker with no login use the API as admin. It is exploited, and no workaround exists. Upgrade and check the logs.

If your stores, clinics, or offices share one network through Cisco SD-WAN, one server controls all of them: the SD-WAN Manager. On September 30, Cisco disclosed Cisco SD-WAN Manager CVE-2026-76504, a critical authentication bypass with a CVSS score of 9.8. Attackers already use it. There is no workaround. The fix is an upgrade, then a look at the logs to see if someone got in before you patched.

What actually happened

Per Cisco's advisory, the Manager handles URI encoding in an HTTP request incorrectly. A crafted request gets around an authentication rule on one API endpoint. The result: an attacker with no credentials can use that API as the admin user. The attacker only needs to reach the Manager's API over the network.

Cisco says its incident response team became aware of active exploitation in September 2026. The Hacker News reports that Cisco found the flaw while it worked on a support case.

Fixed releases:

  • 20.9 → 20.9.10.1
  • 20.12 → 20.12.8.2
  • 20.15 → 20.15.6.1
  • 20.18 → 20.18.4.1
  • 26.1 → 26.1.2.1
  • 26.2 → 26.2.1
  • Earlier than 20.9 → migrate to a fixed release

Cisco says cloud-hosted customers got the fix automatically in release 20.15.605. Cisco offers a temporary "Live Protect" shield, but it warns that the shield can block legitimate logins that use URI encoding.

Why it matters for your business

The Manager is the keys to every site. SD-WAN centralizes policy for all of your locations. Admin access to the Manager is admin access to the network design of the whole business, not to one router.

"No workaround" means the clock is real. You cannot turn off a feature and wait. If your managed service provider runs the Manager for you, ask them today which release you are on and when they upgraded.

Patching does not tell you if you were already breached. Cisco lists what to look for: requests that contain %6a_security_check (a URI-encoded "j") in /var/log/nms/containers/service-proxy/serviceproxy-access.log, and vmanage-server.log entries for viptela-reserved- accounts from sources you do not know. Check before you call this closed.

The management interface should never face the internet. Cisco's main mitigation advice is to restrict access to the Manager and filter it behind a firewall. That is good practice for every admin console you own.

Key takeaways

  • CVE-2026-76504 (CVSS 9.8) lets an unauthenticated attacker use the SD-WAN Manager API as admin
  • Cisco confirms active exploitation; there is no workaround
  • Upgrade to the fixed release for your train (for example, 20.15.6.1 or 26.2.1)
  • Search the service-proxy and vmanage-server logs for the indicators Cisco lists
  • Put the Manager API behind a firewall, away from untrusted networks

Not sure who patches the box that runs your network? We map every admin console, appliance, and self-hosted tool in a business, name an owner for each, and set up the update plan. See what we build, or ask us to check your stack.

Sources: Cisco security advisory cisco-sa-sdwan-webauth-xr8beuuU, The Hacker News.

  • #cisco
  • #cve-2026-76504
  • #sd-wan
  • #patch-management
  • #network-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.