CVE-2026-76504 affecting Cisco Catalyst SD-WAN Manager

This section contains time sensitive announcements about specific cyber threats, vulnerabilities and scams. Each alert has information you need to be aware of, and what actions to take to mitigate any risk to you or your organisation.

Subscribe to our updates to be notified as soon as we publish an alert.

1:40PM, 1 October 2026

TLP Rating: Clear

CVE-2026-76504 affecting Cisco Catalyst SD-WAN Manager

The NCSC is aware of a critical vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has been reported as being actively exploited in the wild:

  •  CVE-2026-76504 (CVSS: 9.8): Authentication bypass vulnerability that allows an unauthenticated remote attacker to gain administrator access to Cisco Catalyst SD-WAN Manager.

What's happening

Systems affected

This vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration.

Cisco Catalyst SD-Wan software release First fixed release
Earlier than 20.9 Migrate to a fixed release.
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

What this means

Successful exploitation could allow an unauthenticated remote attacker to bypass authentication and gain administrator-level access to affected systems.

Cisco has reported active exploitation of this vulnerability and recommends affected organisations upgrade to a fixed software release as soon as possible.

What to look for

How to tell if you're at risk

Organisations running Cisco Catalyst SD-WAN Manager, particularly systems accessible from the internet, should determine whether they are running a vulnerable software release.

How to tell if you're affected

Organisations should review the following log files for unexpected requests containing references to j_security_check from unknown IP addresses. Note: this is only an example, and the vulnerability will allow any one character that is encoded in the request to be used to exploit the vulnerability.

 

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log
  • /var/log/nms/vmanage-server.log
     

Cisco has published detailed indicators of compromise and investigation guidance in their vendor advisory. External Link

What to do

Prevention

Organisations should upgrade affected Cisco Catalyst SD-WAN Manager deployments to a fixed software release as soon as possible. 

More information

Read more about this alert on the vendor website:

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability External Link

If you require more information or further support, submit a report on our website:

Report an incident