1:40PM, 1 October 2026
TLP Rating:
CVE-2026-76504 affecting Cisco Catalyst SD-WAN Manager
The NCSC is aware of a critical vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has been reported as being actively exploited in the wild:
-
CVE-2026-76504 (CVSS: 9.8): Authentication bypass vulnerability that allows an unauthenticated remote attacker to gain administrator access to Cisco Catalyst SD-WAN Manager.
What's happening
Systems affected
This vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration.
| Cisco Catalyst SD-Wan software release | First fixed release |
| Earlier than 20.9 | Migrate to a fixed release. |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
What this means
Successful exploitation could allow an unauthenticated remote attacker to bypass authentication and gain administrator-level access to affected systems.
Cisco has reported active exploitation of this vulnerability and recommends affected organisations upgrade to a fixed software release as soon as possible.
What to look for
How to tell if you're at risk
Organisations running Cisco Catalyst SD-WAN Manager, particularly systems accessible from the internet, should determine whether they are running a vulnerable software release.
How to tell if you're affected
Organisations should review the following log files for unexpected requests containing references to j_security_check from unknown IP addresses. Note: this is only an example, and the vulnerability will allow any one character that is encoded in the request to be used to exploit the vulnerability.
- /var/log/nms/containers/service-proxy/serviceproxy-access.log
- /var/log/nms/vmanage-server.log
Cisco has published detailed indicators of compromise and investigation guidance in their vendor advisory. External Link
What to do
Prevention
Organisations should upgrade affected Cisco Catalyst SD-WAN Manager deployments to a fixed software release as soon as possible.
More information
Read more about this alert on the vendor website:
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability External Link
If you require more information or further support, submit a report on our website: