Cisco Catalyst SD-WAN Manager CVE-2026-76504: Auth Bypass Response Guide
CVE-2026-76504 is an authentication bypass in Cisco Catalyst SD-WAN Manager caused by improper handling of URL/hex-encoded request paths in its session-based API authentication. A remote attacker with no credentials can craft a request that the Manager treats as already-authenticated, granting admin-level access to the API — full control over the SD-WAN fabric it manages, including route tables, device configuration, and certificate trust. Cisco confirmed active exploitation on September 30, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day with a federal remediation deadline of October 3, 2026. There is no workaround; patching is the only remediation.
Why This One Is Worse Than a Typical Manager Bug
SD-WAN Manager is the single control plane for an organization's entire SD-WAN fabric — compromising it does not expose one device, it exposes the routing and configuration authority over every site the fabric connects. An unauthenticated attacker who reaches the admin API can push configuration changes, extract credentials and certificates stored in the Manager, or pivot into every branch and data-center edge device under its control.
This is at least the fourth SD-WAN Manager authentication-related flaw Cisco has patched since May 2026, and it is not covered by any of the earlier fixes — a Manager instance patched for the May or June advisories is still vulnerable to this one and needs this update separately.
Determine Exposure
Exposure is purely version-based; there is no optional feature flag that disables the vulnerable code path.
- •Any Catalyst SD-WAN Manager instance earlier than 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1 (whichever is the next fixed release on its train) is vulnerable
- •Releases earlier than the 20.9 train have no direct fix — these must be migrated to a supported, patched release rather than updated in place
- •Check whether the Manager's admin API/HTTPS management interface is reachable from outside the management network — internet-facing instances are the most urgent to remediate
Immediate Response Steps
With a 3-day federal KEV window and confirmed active exploitation, this supersedes routine patch scheduling.
- •Patch to the applicable fixed release (20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1) immediately; there is no compensating configuration workaround
- •Instances on a pre-20.9 train must be migrated to a supported release — plan the migration as an emergency change, not the next maintenance window
- •Restrict management-plane access to the SD-WAN Manager API to trusted management networks only, as defense-in-depth alongside patching, not as a substitute for it
- •Review SD-WAN Manager audit logs for unexpected admin-level API calls, new local users, or configuration pushes in the days before patching, since Cisco has confirmed in-the-wild exploitation
- •Rotate certificates and credentials stored in or managed by the Manager if any sign of unauthorized access is found
Regulatory Note for India-Based Organizations
A confirmed compromise of the SD-WAN control plane — unauthorized admin-API access, configuration changes, or credential exfiltration — is a security incident under CERT-In's six-hour reporting mandate, and may also trigger DPDP Act breach-notification obligations if the fabric carries personal data in transit that was exposed as a result. Absent confirmed compromise, the obligation right now is emergency patching.
References
Primary sources for the material above. Standards are cited by identifier so they stay findable as publishers reorganise their sites.
- Cisco Security Advisory — Catalyst SD-WAN Manager Authentication Bypass Vulnerability (CVE-2026-76504), 2026-09-30
- CISA — Known Exploited Vulnerabilities Catalog, entry added 2026-09-30, due 2026-10-03