Cisco has released security updates for a critical vulnerability in Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. Tracked as CVE-2026-76504, the flaw can allow an unauthenticated remote attacker to access the management system with administrator privileges.
Cisco says the vulnerability is being exploited in attacks. The issue affects Catalyst SD-WAN Manager regardless of system configuration, although the advisory does not identify the affected software releases or list the fixed versions in the available evidence. Administrators should consult Cisco’s official security advisory to match their deployment with an appropriate fixed release.
How CVE-2026-76504 works
The problem lies in API session-based authentication management. Cisco describes improper handling of URI encoding in an HTTP request, which can bypass an authentication rule intended to restrict access to a specific API endpoint. A specially crafted request can therefore reach the API without authentication and obtain access as the admin user.
Cisco’s advisory says there is no workaround that addresses the vulnerability. Its recommended action is to install a fixed software release. The available information does not establish whether every exposed system has been compromised, but internet-facing Catalyst SD-WAN Manager systems with exposed ports are at risk of exposure.
Why it matters
Catalyst SD-WAN Manager provides centralized administration for SD-WAN environments. An authentication bypass at that layer is significant because access is not limited to an ordinary user account: the reported outcome is administrative access to the management API. Cisco has also confirmed active exploitation, so organizations running the product should treat patching and review of exposed systems as time-sensitive defensive work.
What administrators can check
After reviewing the affected deployment and applying the relevant Cisco update, administrators can inspect the following logs for suspicious requests. Cisco cautions that the indicators may also appear during normal operations and must be compared with the organization’s expected network activity.
/var/log/nms/containers/service-proxy/serviceproxy-access.log: look for requests related toj_security_checkfrom unknown or unauthorized IP addresses./var/log/nms/vmanage-server.log: look for relatedj_security_checkactivity involving user names that begin withviptela-reserved-.
Cisco’s example includes the encoded character %6a in a request path, but the advisory says this is only an example and that any one encoded character could be used in the request. The presence of a matching entry should therefore be investigated rather than treated as proof of compromise on its own.
Organizations that need help determining whether a Catalyst SD-WAN Manager system was compromised can open a Severity 3 case with the Cisco Technical Assistance Center and include CVE-2026-76504 in the case title. Cisco recommends collecting an admin-tech file with the request admin-tech command before opening the case so it can be provided for review.
The evidence confirms that Cisco has issued fixes and that exploitation has been reported, but it does not provide the affected or fixed software version ranges. Administrators should use Cisco’s advisory—not a generic version assumption—to identify the correct update for their installation.
Alex Mira is a fictitious AI-assisted author created for the Toolslib blog. Designed to support cybersecurity education, Alex writes about malware trends, software utilities, privacy practices, Windows internals, and practical defensive workflows. Articles published under Alex’s name are generated or assisted by AI and reviewed according to Toolslib’s editorial standards before publication.
Stay Updated with ToolsLib! 🚀
Join our community to receive the latest cybersecurity tips, software updates, and exclusive insights straight to your inbox!