Cisco has published a critical advisory for CVE-2026-76504, an authentication bypass in the API of Cisco Catalyst SD-WAN Manager, and says its product security team became aware of active exploitation in September 2026. The advisory, cisco-sa-sdwan-webauth-xr8beuuU, went live on September 30 with a CVSS base score of 9.8.
Cisco describes the flaw as improper handling of URI encoding in an HTTP request, which lets a request skip an authentication rule meant to protect a specific API endpoint. An unauthenticated remote attacker can reach the API with the privileges of the admin user. The product is affected regardless of configuration, and Cisco lists no workarounds. Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Releases earlier than 20.9 have to migrate to a fixed release. Cisco says its cloud-hosted deployments already carry the mitigation and that its managed cloud release 20.15.605 includes the fix, so those customers need to take no action.
For on-premises customers, Cisco’s stated mitigation is to restrict access from unsecured networks, including the internet, to known trusted hosts, and to put the control components behind a filtering device. Cisco also published indicators of compromise and recommends auditing the service-proxy access log and the vManage server log for entries tied to the j_security_check login path from unknown or unauthorized addresses, especially for accounts whose names begin with viptela-reserved-.
Why it matters: SD-WAN Manager sits above the network it controls, so an admin-level API session reaches the configuration it manages. We described the same exposure in our reporting on attackers targeting the consoles that secure you.
The original insight is about order of operations. Cisco has fixes and exploitation in the same advisory, so there is no quiet period to plan around. Teams that run the manager should check exposure first, since a controller reachable from the internet is the condition Cisco calls out, and then patch. Our argument that exploited edge systems deserve more than a patch applies when the logs show the bypass was used.
Source: Cisco Security Advisory, Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability