Critical Authentication Bypass in Cisco SD‑WAN Manager (CVE‑2026‑76504) Actively Exploited
What Happened — Cisco disclosed a critical authentication‑bypass flaw (CVE‑2026‑76504) in its Catalyst SD‑WAN Manager that allows unauthenticated remote access with administrator privileges. The vulnerability is being actively exploited in the wild, and the U.S. CISA has added it to its Known Exploited Vulnerabilities catalog.
Why It Matters for Trust & Control Assurance
- The incident highlights the need for robust access‑control safeguards around management interfaces – a core control objective that continuous‑control‑assurance programs are built to verify and evidence.
- It demonstrates why network segmentation and log‑monitoring are essential to detect and contain a breach of privileged management components.
- Verisq’s Access Controls capability can help you continuously validate that only authorized, network‑segmented entities can reach critical SD‑WAN APIs and provide audit‑ready evidence of compliance.
Who Is Affected – Enterprises and service providers that deploy Cisco SD‑WAN (telecom, cloud‑infra, large‑scale corporate networks).
Recommended Actions
- Apply the Cisco‑provided patches immediately.
- Restrict SD‑WAN Manager access to trusted networks; place the manager behind firewalls or zero‑trust gateways.
- Enable and retain detailed API request logs (serviceproxy‑access.log, vmanage‑server.log) and monitor for the URI‑encoded “%6a” pattern or unauthorized
j_security_checkcalls. - Conduct a post‑patch audit of your access‑control policies and segmentation architecture.
Technical Notes – The flaw stems from improper handling of URI encoding in an HTTP request to the SD‑WAN Manager API, enabling an authentication bypass. CVSS 9.8 (critical). No known work‑arounds; mitigation relies on patching and network isolation. Source: DataBreachToday