Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Authentication Bypass in Cisco SD‑WAN Manager (CVE‑2026‑76504) Actively Exploited

Cisco disclosed CVE‑2026‑76504, a critical authentication‑bypass flaw in its SD‑WAN Manager that is being actively exploited. The vulnerability grants unauthenticated remote admin access, underscoring the importance of strong access‑control and audit evidence for compliance readiness.

LiveThreat™ Intelligence · 📅 October 02, 2026· 📰 databreachtoday.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
databreachtoday.com

Critical Authentication Bypass in Cisco SD‑WAN Manager (CVE‑2026‑76504) Actively Exploited

What Happened — Cisco disclosed a critical authentication‑bypass flaw (CVE‑2026‑76504) in its Catalyst SD‑WAN Manager that allows unauthenticated remote access with administrator privileges. The vulnerability is being actively exploited in the wild, and the U.S. CISA has added it to its Known Exploited Vulnerabilities catalog.

Why It Matters for Trust & Control Assurance

  • The incident highlights the need for robust access‑control safeguards around management interfaces – a core control objective that continuous‑control‑assurance programs are built to verify and evidence.
  • It demonstrates why network segmentation and log‑monitoring are essential to detect and contain a breach of privileged management components.
  • Verisq’s Access Controls capability can help you continuously validate that only authorized, network‑segmented entities can reach critical SD‑WAN APIs and provide audit‑ready evidence of compliance.

Who Is Affected – Enterprises and service providers that deploy Cisco SD‑WAN (telecom, cloud‑infra, large‑scale corporate networks).

Recommended Actions

  • Apply the Cisco‑provided patches immediately.
  • Restrict SD‑WAN Manager access to trusted networks; place the manager behind firewalls or zero‑trust gateways.
  • Enable and retain detailed API request logs (serviceproxy‑access.log, vmanage‑server.log) and monitor for the URI‑encoded “%6a” pattern or unauthorized j_security_check calls.
  • Conduct a post‑patch audit of your access‑control policies and segmentation architecture.

Technical Notes – The flaw stems from improper handling of URI encoding in an HTTP request to the SD‑WAN Manager API, enabling an authentication bypass. CVSS 9.8 (critical). No known work‑arounds; mitigation relies on patching and network isolation. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/breach-roundup-cisco-sd-wan-flaw-under-attack-a-33001 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →