Active Attacks Target Critical Cisco SD-WAN Manager Vulnerability
KI-generiertes Bild

Active Attacks Target Critical Cisco SD-WAN Manager Vulnerability

Cisco disclosed a critical zero-day flaw (CVE-2026-76504) in its SD-WAN Manager that attackers are actively exploiting to bypass authentication and gain admin a…

Cisco has disclosed that attackers are actively exploiting a zero-day vulnerability in its Catalyst SD-WAN Manager, a central platform that organizations use to control their software-defined wide area networks. The flaw, tracked as CVE-2026-76504, allows an unauthenticated remote attacker to bypass authentication entirely and gain full administrative access through the Manager’s API. Because it requires no credentials and only the ability to send a specially crafted HTTP request, any SD-WAN Manager exposed to the internet is at risk of compromise.

The vulnerability carries a CVSS severity score of 9.8 out of 10, reflecting its critical nature. It exists in the portion of the Manager’s API that handles login sessions. The root cause is a mishandling of URI encoding in an HTTP request. By encoding a character in the request path used for session-based logins, an attacker can trick the system into skipping an authentication check designed to protect a specific API endpoint. In Cisco’s example, the normal request path is j_security_check, but sending /%6a_security_check (where %6a is the URI-encoded representation of the letter j) can bypass the restriction. Any single character in the request can be encoded, so the exact pattern may vary.

Cisco’s Product Security Incident Response Team became aware of active exploitation in September 2026 while the company’s Technical Assistance Center was handling a support case. The advisory did not specify how many customers were targeted, when the attacks began, who was behind them, or what the attackers achieved. No product other than SD-WAN Manager is affected, and there is no workaround. Cisco has released fixed versions for each supported release train:

- Releases earlier than 20.9: migrate to a fixed release
- 20.9: fixed in 20.9.10.1
- 20.12: fixed in 20.12.8.2
- 20.15: fixed in 20.15.6.1
- 20.18: fixed in 20.18.4.1
- 26.1: fixed in 26.1.2.1
- 26.2: fixed in 26.2.1

This vulnerability is separate from three earlier Cisco SD-WAN flaws addressed in May and June 2026. The fixed releases for those older issues are all earlier versions than the ones listed above, so a system updated only for the May or June flaws still needs this new patch. Notably, the advisory does not cover certain release trains (20.10, 20.11, 20.13, 20.14, 20.16) that were mentioned in earlier SD-WAN advisories, nor does it mention Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP) deployment types. Cisco SD-WAN Cloud (Cisco Managed) customers are already on a fixed release (20.15.605) and need to take no action.

To detect potential compromise, Cisco provided specific indicators. Administrators should check two log files: /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log. Look for entries containing j_security_check from unknown or unauthorized IP addresses, especially any where characters are URI-encoded, such as %6a for j. Also examine entries where the user name starts with viptela-reserved-, because these belong to reserved system service accounts that could be misused. Cisco warns that these log entries can also appear during normal operation, so each match must be verified against routine activity to avoid false positives.

While no detection rule is provided, customers who suspect a breach can open a Severity 3 case with Cisco TAC, including CVE-2026-76504 in the case title. They should run the command request admin-tech on the Manager beforehand so the output file can be reviewed. The advisory does not state whether upgrading will remove an already-established attacker. Cisco’s past advisories for similar SD-WAN flaws noted that a software update alone would not eliminate a confirmed compromise, so collecting the admin-tech output before patching is advised.

For organizations that cannot patch immediately, Cisco recommends restricting access to the Manager from unsecured networks such as the internet. If internet-based access is required, allow connections only from known, trusted hosts and place control components behind a firewall. Cisco Catalyst SD-WAN Cloud Hosted environments already have this mitigation in place, and testing showed it to be effective. Additionally, Cisco’s SD-WAN hardening guide advises that administrative interfaces (ports 443, 22, 830) should never be exposed directly to the internet; HTTPS access to the Manager should arrive only from a jump host or a management subnet.

The flaw continues a string of actively exploited Cisco SD-WAN vulnerabilities this year. As of September 30, the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog listed eight Cisco SD-WAN flaws added in 2026. Keeping management interfaces patched and inaccessible from the internet remains a basic security measure that security-focused IT services like AEU-I help enforce for businesses, ensuring that network control points are monitored and updated before a flaw can be turned into a breach.

So schützen Sie sich

  1. Ask your IT provider or system administrator whether any Cisco SD-WAN Manager devices in your organization are running the affected versions and if they have been patched against CVE-2026-76504.
  2. Ensure that management interfaces for your network devices are not directly accessible from the internet; they should be behind a firewall and accessible only through a secure jump host or VPN.
  3. Regularly check for and apply security updates for all network equipment, especially when vendors announce actively exploited flaws.
  4. Monitor logs for unusual login attempts or activity from unknown IP addresses, particularly any entries referencing 'j_security_check' with unexpected characters.
  5. If you suspect a compromise, contact your security provider immediately and preserve log files for investigation.

Schwachstellen & Lösungen

Begriffe Erklärt

  • CVE A unique identifier for a specific software security flaw, used globally to track vulnerabilities.
  • CVSS A scoring system that rates the severity of a vulnerability from 0 to 10, with 10 being the most critical.
  • authentication bypass A security weakness that allows someone to skip the normal login process and access a system without a password.
  • URI encoding A way to represent characters in a web address using a percent sign and numbers, such as %6a for the letter j.
  • SD-WAN Software-Defined Wide Area Network, a technology that uses software to manage and route traffic between an organization’s offices and data centers.
  • zero-day A vulnerability that attackers are already using before the software maker has released a fix.

Verwandte AEU-Dienste

  • AEU-I IT- und Sicherheitsberatung