Cisco Warns of Actively Exploited Critical SD-WAN Flaw
Cisco has confirmed that a critical flaw in its Catalyst SD-WAN Manager is actively being exploited, urging customers to upgrade their systems immediately. The vulnerability, tracked as CVE-2026-76504, allows an unauthenticated remote attacker to bypass authentication and gain administrator-level access by sending a crafted HTTP request. Cisco has rated this flaw with a CVSS severity score of 9.8 out of 10, indicating its high risk. The company discovered the active exploitation in September and has advised rapid upgrades to mitigate the threat.
The flaw affects the product's API and is particularly concerning because SD-WAN Manager is used to manage enterprise-wide software-defined networks. A successful exploit could grant attackers full control over network configurations and monitoring, posing a significant risk to affected organizations. Cisco has not disclosed the number of affected customers or confirmed compromises but emphasizes the urgency of applying the necessary patches.
To address the issue, Cisco has released fixed software versions for various supported release branches. Customers using version 20.9 should upgrade to 20.9.10.1, while those on older versions must migrate to a fixed release. The company also notes that its managed cloud service, Cisco SD-WAN Cloud, has been addressed in release 20.15.605, requiring no customer action. Cisco advises organizations to block access from unsecured networks and restrict management access to trusted hosts as a temporary measure.
Security agencies, including New Zealand’s National Cyber Security Centre and Canada’s Centre for Cyber Security, have echoed Cisco’s warnings, reinforcing the urgency of the situation. Organizations are advised to review logs for unusual activity, particularly involving the j_security_check endpoint, and to contact Cisco’s Technical Assistance Center if they suspect a compromise.