Cisco SD-WAN Manager Flaw Exposes Thousands of Devices to Admin Access Attacks
Cisco has fixed a critical vulnerability in its SD-WAN management software that allowed attackers to gain admin access without authentication. The bug, tracked as CVE-2026-76504, carried a CVSS score of 9.8 and was exploitable remotely without credentials or user interaction.
The vulnerability affected Cisco Catalyst SD-WAN Manager releases 20.9 and earlier, 20.12, 20.15, 20.18, 26.1, and 26.2. To mitigate the issue, customers were advised to upgrade to their respective patched versions. The flaw was caused by improper handling of URI encoding in HTTP requests, which enabled attackers to bypass an authentication control.
Sakshi Grover, senior research manager for cybersecurity at IDC Asia/Pacific, noted that the barrier to exploitation was very low once the management interface was reachable. She warned that compromising the management layer could give attackers considerable leverage and allow them to understand network topology, modify templates or policies, weaken segmentation, establish persistence, or distribute unauthorized configuration changes.
Cisco provided organizations with indicators to check whether attackers had already targeted their SD-WAN Manager instances. The company recommended examining log files for requests to the 'j_security_check' endpoint originating from unknown or unauthorized IP addresses and collecting admin-tech files for analysis.