Cisco Fixes Critical Flaw in Catalyst SD-WAN Manager as Attacks Are Underway
Cisco has released fixes for CVE-2026-76504 in Catalyst SD-WAN Manager. The critical flaw allows remote, unauthenticated attackers to gain administrator privileges, and the vendor has confirmed active exploitation.

Cisco Catalyst SD-WAN Manager has received fixes for the critical vulnerability CVE-2026-76504, which attackers are reportedly already actively exploiting, according to the vendor. The flaw has a CVSS score of 9.8 and allows a remote, unauthenticated attacker to bypass API authentication and obtain administrator privileges.
Cisco published its security advisory on September 30, 2026. Cisco PSIRT stated that it learned of active exploitation in September. New Zealand’s National Cyber Security Centre (NCSC) subsequently issued its own alert on October 1 and recommended promptly updating affected systems.
Cisco Catalyst SD-WAN Manager and Authentication Bypass
CVE-2026-76504 affects Cisco Catalyst SD-WAN Manager, a centralized interface for managing SD-WAN infrastructure. Exploitation does not require credentials: an attacker can bypass authentication checks through the API and gain administrative access.
Given the manager’s role, a compromise may have a broader impact than an attack on an isolated network device. The administrative interface is used to manage network components from a single location.
According to Cisco, deployments are vulnerable regardless of configuration. The vendor has released fixed versions but does not provide a full workaround that could replace the update.
What Administrators Should Do
The priority is to deploy the fixed versions made available by Cisco. Organizations should also restrict access to the Catalyst SD-WAN Manager interface to trusted networks and hosts, especially if the system is accessible from the internet. Cisco warns that internet-facing systems face greater risk.
The vendor recommends checking logs for requests related to j_security_check that originate from unknown or unauthorized IP addresses. Such checks may help identify suspicious activity related to this flaw.
- identify all Catalyst SD-WAN Manager deployments,
- update them to a fixed version from Cisco,
- restrict network access to the administrative interface to trusted sources,
- check logs for j_security_check requests from unauthorized IP addresses.
Cisco Has Not Yet Described the Scope of the Attacks
Cisco confirmed active exploitation but did not disclose the attackers’ identity, the scope of the campaign, or the number of potentially compromised organizations. As a result, details about the attackers’ methods beyond the indicators provided by the vendor are also unavailable.
The supplied materials and secondary reporting also state that CVE-2026-76504 was added to the CISA Known Exploited Vulnerabilities catalog. However, the relevant catalog entry could not be loaded directly during verification, so confirmation of this listing and any required remediation deadline should be monitored in official CISA updates.
Further information may come from new technical details from Cisco, possible attribution of the attacks, or notifications from organizations that discover a connection between their incidents and CVE-2026-76504.
Sources
- Cisco Security Advisory – Confirms CVE-2026-76504, CVSS 9.8, active exploitation, the impact on a remote unauthenticated attacker, IOCs, the absence of a workaround, and available fixes.
- NCSC New Zealand – Independently confirms the alert about active exploitation, the affected product, the risk of administrative access, and the update recommendation.
- CISA Known Exploited Vulnerabilities Catalog – The supplied entry lists CVE-2026-76504 as a vulnerability recorded in the catalog of known exploited vulnerabilities and describes the possibility of remote administrative access.
Verified and updated: 10/01/2026 06:20



