Cisco has released emergency security updates for a critical vulnerability in its Catalyst SD-WAN Manager software after confirming that hackers are actively exploiting the flaw. The security weakness could allow attackers to bypass authentication and gain administrator-level access to affected systems without valid login credentials.
The vulnerability, tracked as CVE-2026-76504, carries a severity score of 9.8 out of 10. Cisco disclosed the issue on September 30, warning that successful exploitation could give an unauthorised attacker extensive access to the network management platform.
Cisco Catalyst SD-WAN Manager is used by organisations to centrally manage and monitor networks connecting offices, data centres and other locations.
The company confirmed that its security response team became aware of active exploitation in September. However, it has not publicly identified the attackers, disclosed the number of affected organisations or provided details about the attacks.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
How the Vulnerability Allows Hackers to Bypass Authentication
The security flaw exists in how Cisco Catalyst SD-WAN Manager handles authentication requests made through its application programming interface, or API.
An API allows different software components to communicate and exchange information. In this case, certain API functions are intended to be accessible only after a user has been authenticated.
However, Cisco discovered that the software improperly handles encoded characters in certain web requests.
By manipulating these characters, an attacker can create a request that bypasses an authentication rule protecting a particular API endpoint.
This means an attacker could potentially access the affected interface without entering a username or password.
More importantly, successful exploitation could provide the attacker with the same API privileges as an administrator.
The vulnerability is particularly serious because attackers can attempt exploitation remotely. They do not need an existing account, special access permissions or interaction from an employee.
Cisco confirmed that the vulnerability affects Catalyst SD-WAN Manager regardless of its system configuration.
Why Administrator Access Creates Serious Security Risks
Catalyst SD-WAN Manager is responsible for centrally managing software-defined wide-area networks.
In simple terms, these networks allow organisations to connect offices, applications and infrastructure across different locations while controlling network traffic through a central management system.
A security weakness in that management system can therefore create risks beyond a single compromised application.
An attacker who obtains administrator-level API access could potentially interact with sensitive management functions and attempt further unauthorised activities.
Depending on the affected environment and the attacker’s subsequent actions, this could expose network configurations or create opportunities for additional attacks.
However, Cisco has not publicly established what the attackers exploiting CVE-2026-76504 have achieved after obtaining access.
The confirmed vulnerability involves authentication bypass and administrator-level API access. Any additional compromise would require further investigation.
Cisco Releases Security Updates as Active Exploitation Confirmed
Cisco has released software updates addressing the vulnerability across multiple supported Catalyst SD-WAN software versions.
Customers running affected installations have been advised to upgrade to a fixed release.
For organisations using the 20.9 software branch, the vulnerability is addressed in version 20.9.10.1.
The fixed releases for other supported branches include versions 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1.
Organisations operating versions earlier than 20.9 must migrate to an appropriate fixed release.
Cisco has also addressed the vulnerability in its managed SD-WAN cloud service through release 20.15.605. The company says customers using that managed cloud service do not need to take additional action to deploy the fix.
Importantly, Cisco has confirmed that no workaround completely addresses the security flaw.
For organisations operating on-premises deployments, the company recommends restricting management access from unsecured networks, including the public internet.
Where external access is necessary, administrators should restrict connections to known and trusted systems.
These restrictions can reduce exposure but are not substitutes for installing the security updates.
Cisco Shares Warning Signs to Help Identify Possible Compromise
Cisco has also published technical indicators to help administrators investigate whether attackers have attempted to exploit the vulnerability.
The company recommends examining access logs associated with the Catalyst SD-WAN Manager service proxy.
Administrators should look for suspicious authentication-related requests originating from unknown or unauthorised IP addresses.
Cisco also recommends reviewing application logs for unusual activity involving certain reserved system accounts.
These records may help investigators identify requests designed to bypass the software’s authentication controls.
However, Cisco cautions that some similar activity may also occur during normal operations. Security teams must therefore examine suspicious records in the context of their own network environments.
Organisations that suspect their systems have been compromised can contact Cisco’s Technical Assistance Center for assistance.
What this means for you
Organisations using Cisco Catalyst SD-WAN Manager should urgently identify vulnerable installations and apply the appropriate security updates. Network administrators should also restrict unnecessary internet access to management interfaces and examine system logs for suspicious authentication activity, particularly because Cisco has confirmed active exploitation.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics