Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Authentication Bypass in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑76504) Enables Remote Admin Access

Cisco Catalyst SD‑WAN Manager suffers a CVE‑2026‑76504 authentication bypass that allows unauthenticated attackers to gain admin rights. The flaw is actively exploited and scores 9.8 CVSS, prompting urgent patching and tighter network segregation for audit readiness.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Authentication Bypass in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑76504) Enables Remote Admin Access

What It Is – Cisco Catalyst SD‑WAN Manager contains an improper URI‑encoding handling bug that lets an unauthenticated attacker bypass the session‑authentication check and obtain administrator‑level access to the management API.

Exploitability – The flaw is actively exploited in the wild (CISA KEV listing) and carries a CVSS v3.1 base score of 9.8 (Critical).

Affected Products – All on‑premise Cisco Catalyst SD‑WAN Manager releases prior to the fixed versions: 20.9 → 20.9.10.1, 20.12 → 20.12.8.2, 20.15 → 20.15.6.1, 20.18 → 20.18.4.1, 26.1 → 26.1.2.1, 26.2 → 26.2.1.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous verification that authentication controls are correctly enforced across API surfaces.
  • Highlights the importance of maintaining up‑to‑date patch evidence as part of a defensible audit trail.
  • Forces organizations to prove network‑level segregation (firewalling, internet exposure) when exposing management interfaces, a key control for enterprise‑grade trust.

Recommended Actions

  • Upgrade every SD‑WAN Manager instance to the fixed release listed above.
  • Immediately block internet access to the manager UI; place the component behind a firewall that only allows trusted host traffic.
  • Enable and retain detailed API request logging (serviceproxy‑access.log) and review for unknown j_security_check requests.
  • Incorporate the patch‑status check into your continuous control‑monitoring pipeline to generate evidence for audit reviews.

Source: Security Affairs – CISA adds Cisco Catalyst SD‑WAN Manager flaw to KEV catalog

📰 Original Source
https://securityaffairs.com/200152/security/u-s-cisa-adds-cisco-catalyst-sd-wan-manager-flaw-to-its-known-exploited-vulnerabilities-catalog.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →