Cisco’s SD-WAN Admin Bypass Is Being Exploited

Matthew Leo · Published October 2, 2026 · News

A network engineer works on a laptop beside an equipment rack in a server room.

Cisco is warning customers to patch a critical authentication-bypass flaw in Catalyst SD-WAN Manager after detecting active exploitation. The vulnerability can give a remote attacker administrator access to the management API without valid credentials.

There is no workaround. Cisco says every affected Manager must be upgraded, including each member of a cluster and both sides of a disaster-recovery deployment.

What the flaw allows

The vulnerability is tracked as CVE-2026-76504 and carries a CVSS score of 9.8 out of 10. Cisco's security advisory says the problem comes from improper handling of encoded characters in HTTP requests to the SD-WAN Manager API.

An attacker can exploit it by sending a specially crafted request to an affected system. Successful exploitation allows access to the API with administrator privileges. That level of control can expose configuration data and create a path to alter how the wider SD-WAN environment is managed.

The flaw affects Cisco Catalyst SD-WAN Manager, formerly called vManage. Cisco says it affects all configurations of the product when they run a vulnerable release.

Do not erase the useful evidence

Cisco's remediation instructions have an unusual but important order. Administrators should collect an admin-tech bundle from every Manager before upgrading, then patch immediately and open a Cisco Technical Assistance Center case so the bundles can be scanned for indicators of compromise.

The company is clear that organizations should not wait for Cisco to finish that scan before installing a fixed release. Preserving the files first keeps diagnostic evidence that may be lost during the upgrade; patching next closes the vulnerability.

Cisco's step-by-step remediation document says to collect the Log and Tech options. Core files are not required. Clustered systems need a bundle from every node, and disaster-recovery setups need bundles from both the primary and secondary environments.

Which releases contain the fix

Organizations must stay within their current major release unless Cisco TAC gives different guidance. Cisco lists these first fixed versions:

Earlier major branches listed in the advisory have no fixed release. Customers on those versions need to move to a supported branch. Cisco says its cloud-hosted SD-WAN offering was remediated in release 20.15.605, but customers still need to confirm whether they operate any self-managed Manager nodes.

Why the active exploitation changes the response

Cisco discovered the vulnerability while resolving a support case and says its Product Security Incident Response Team became aware of exploitation in September 2026. That makes this more than a theoretical risk.

Rapid7's independent assessment also describes the issue as an internet-facing authentication bypass with exploitation in the wild. The security firm notes that exposed management interfaces are especially urgent, but restricting exposure is not a substitute for upgrading.

An organization that patches without reviewing evidence can still leave behind changes made before the fix. After the upgrade, administrators should examine accounts, access controls, configuration changes and any integrations or credentials reachable through the management environment. Cisco says TAC will provide additional remediation instructions if its scan finds indicators of compromise.

What Canadian organizations should do

Canadian telecom providers, public agencies, universities and large businesses use SD-WAN to connect offices and remote sites. Cisco has not identified Canadian victims, so there is no basis to claim a Canada-specific campaign. The product's role still makes the advisory relevant here: one compromised management plane can affect connectivity across many locations.

Teams should identify every Catalyst SD-WAN Manager, record its version and ownership, collect the diagnostic bundles, upgrade to the appropriate fixed release and open the TAC case Cisco requests. Managed-service customers should get written confirmation that their provider completed those steps and checked for earlier compromise.

The short version is operational: preserve evidence first, patch immediately after, then verify whether the attacker arrived before the fix.

Tags: Cisco, SD-WAN, cybersecurity, CVE-2026-76504

Read on Mapletechie