Cisco SD-WAN Manager CVE-2026-76504: Patch Critical Admin API Authentication Bypass


Cisco disclosed CVE-2026-76504 on September 30, 2026, a critical authentication-bypass vulnerability in Catalyst SD-WAN Manager that can give an unauthenticated remote attacker access to the product API with admin-user privileges. Cisco PSIRT says the vulnerability has been exploited in the wild.

The flaw carries a CVSS 3.1 score of 9.8. It affects supported Catalyst SD-WAN Manager release trains from 20.9 through 26.2. Fixed releases are available, and administrators running affected versions should upgrade promptly.

Release train Fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

Deployments older than 20.9 are end of support and should move to a supported release. Cisco's advisory is the authoritative source for the applicable upgrade path and any subsequent revision to fixed software.

What CVE-2026-76504 allows

Cisco describes the issue as improper handling of URI encoding in an HTTP request. The behavior can bypass an authentication rule protecting a specific API endpoint. A crafted request sent to an affected Catalyst SD-WAN Manager can therefore reach the API without valid authentication and obtain the privileges of the admin user.

The attack is remote and requires neither prior privileges nor user interaction according to Cisco's CVSS vector. The consequence is particularly significant because SD-WAN Manager is the management plane for the SD-WAN fabric: administrator-level API access can expose configuration and management functions that operators normally protect as privileged infrastructure.

Cisco has reported malicious exploitation. That changes the operational priority from routine vulnerability management to incident-aware remediation: exposed organizations should preserve relevant evidence, review Cisco's indicators-of-compromise guidance, assess the Manager for signs of unauthorized activity, and deploy a fixed release.

Patch floors

The fixed-version table above reflects Cisco's September 30 advisory as independently reproduced by NHS England's National Cyber Security Operations Centre. Operators should use Cisco's Software Checker and release documentation when a deployment has maintenance releases, platform constraints or an upgrade path that requires intermediate steps.

NHS England advises organizations to perform a compromise assessment first, or preserve a device snapshot and relevant logs before patching, because remediation can remove evidence useful to subsequent threat hunting. That sequencing is incident-response guidance for environments with plausible exposure; normal change-control and evidence-retention requirements still apply.

Why older 2026 SD-WAN patches are insufficient

CVE-2026-76504 is a newly disclosed authentication-bypass issue with newer fixed builds than several Catalyst SD-WAN Manager vulnerabilities addressed earlier in 2026. A system updated only to a May or June security floor can therefore remain exposed to this September issue.

Use the running Manager release as the inventory baseline. Compare each Manager against the current Cisco advisory and move to the fixed release in its supported train or a later supported version.

Operational checklist

  1. Identify every Catalyst SD-WAN Manager deployment and record its exact running version.
  2. Compare that version with Cisco's fixed-software table and current Software Checker guidance.
  3. For systems with meaningful exposure, preserve relevant logs and artifacts and review Cisco's indicators of compromise before remediation where operationally feasible.
  4. Upgrade affected Managers to the applicable fixed release or a later supported release.
  5. Review privileged/API activity for unexpected access and follow the Cisco Catalyst SD-WAN hardening guidance after remediation.

The combination of unauthenticated remote reachability, admin-level API access and confirmed exploitation makes CVE-2026-76504 a high-priority update for organizations operating Catalyst SD-WAN Manager.

Sources