Hackers exploit another Cisco SD-WAN flaw for admin access

Published

Cisco has confirmed that attackers are exploiting a critical flaw in Catalyst SD-WAN Manager, the central console many organizations use to run their wide-area networks, and there is no workaround short of patching or cutting the system off from untrusted networks. The bug, tracked as CVE-2026-76504 and rated 9.8 out of 10 on the CVSS scale, lets an unauthenticated remote attacker reach the product's API with the privileges of the admin user.

Cisco published its advisory on September 30, 2026, and said its product security team became aware of exploitation in September. Rapid7's emergent threat response team summarized the advisory the same day and urged customers to upgrade on an emergency basis, outside normal patch cycles, and to check internet-facing systems for signs of compromise.

One encoded character is enough

According to Cisco, the flaw comes from improper handling of URL encoding (CWE-177). A crafted HTTP request can slip past an authentication rule that protects a specific API endpoint. Cisco says an attacker can exploit it by encoding any single character in the request, and that the product is vulnerable regardless of how it is configured. Systems with ports exposed to the internet are the ones at risk.

This is the third critical authentication problem in Catalyst SD-WAN control components this year. Earlier in 2026, CVE-2026-20127 and the Rapid7-discovered CVE-2026-20182 hit peering authentication in the vdaemon service, and our earlier coverage documented attackers planting webshells on unpatched SD-WAN devices. Rapid7 notes that CVE-2026-76504 sits in a separate API authentication path, but says the recurrence of these bypasses reinforces the case for emergency remediation.

Upgrade now, and fence off the console until you do

Cisco has shipped fixed releases for every supported train:

The Cisco-managed SD-WAN Cloud service is already fixed in release 20.15.605, and Cisco says no customer action is needed there. On-premises customers who cannot patch immediately should block access from unsecured networks, and where internet access is genuinely required, restrict it to known, trusted hosts behind a filtering device. Cisco says that mitigation is already deployed in its Cloud Hosted environments, and that updates should be applied even where it is in place.

How to check whether you were hit

Because exploitation has occurred, Rapid7 recommends auditing affected systems. Cisco points to two logs:

Cisco cautions that these entries can also appear during standard operations, so they should be weighed against the network's normal posture to avoid false positives. Customers who suspect compromise can open a Severity 3 TAC case with CVE-2026-76504 in the title and attach an admin-tech file generated with the request admin-tech command. Rapid7 says checks for its Exposure Command, Vulnerability Management and Nexpose products are expected in its October 1 content release.

An SD-WAN manager holds the configuration for every branch it controls, which is exactly why attackers keep coming back to it. Three critical authentication failures in one product line in a single year make a strong case for keeping these consoles off the open internet entirely, patched or not.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions