Critical Authentication Bypass in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑76504) Enables Remote Admin Access
What It Is – Cisco Catalyst SD‑WAN Manager contains an improper URI‑encoding handling bug that lets an unauthenticated attacker bypass the session‑authentication check and obtain administrator‑level access to the management API.
Exploitability – The flaw is actively exploited in the wild (CISA KEV listing) and carries a CVSS v3.1 base score of 9.8 (Critical).
Affected Products – All on‑premise Cisco Catalyst SD‑WAN Manager releases prior to the fixed versions: 20.9 → 20.9.10.1, 20.12 → 20.12.8.2, 20.15 → 20.15.6.1, 20.18 → 20.18.4.1, 26.1 → 26.1.2.1, 26.2 → 26.2.1.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous verification that authentication controls are correctly enforced across API surfaces.
- Highlights the importance of maintaining up‑to‑date patch evidence as part of a defensible audit trail.
- Forces organizations to prove network‑level segregation (firewalling, internet exposure) when exposing management interfaces, a key control for enterprise‑grade trust.
Recommended Actions
- Upgrade every SD‑WAN Manager instance to the fixed release listed above.
- Immediately block internet access to the manager UI; place the component behind a firewall that only allows trusted host traffic.
- Enable and retain detailed API request logging (serviceproxy‑access.log) and review for unknown
j_security_checkrequests. - Incorporate the patch‑status check into your continuous control‑monitoring pipeline to generate evidence for audit reviews.
Source: Security Affairs – CISA adds Cisco Catalyst SD‑WAN Manager flaw to KEV catalog