CISA: Cisco Catalyst SD-WAN Auth Bypass Under Active Exploit
Immagine generata dall'IA

CISA: Cisco Catalyst SD-WAN Auth Bypass Under Active Exploit

CISA has added a critical authentication bypass in Cisco Catalyst SD-WAN Manager (CVE-2026-76504) to its Known Exploited Vulnerabilities list after reports of a…

The United States Cybersecurity and Infrastructure Security Agency (CISA) has officially added a severe authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalogue, confirming that the flaw is now being actively exploited in the wild. The entry, published on Wednesday, marks the eighth Cisco SD-WAN related CVE to land on the KEV list in 2026 alone, underscoring how attackers increasingly view the network management platform as a prime target.

The vulnerability, tracked as CVE-2026-76504 and carrying a CVSS severity score of 9.8 out of 10, allows an unauthenticated remote attacker to gain full administrative access to an affected system. The root cause lies in how the product handles URI encoding within HTTP requests sent to its API. Specifically, the software does not properly decode hex-encoded characters in the request path, which an attacker can use to craft a specially formed HTTP request that bypasses the normal login procedure entirely. Successful exploitation grants the attacker direct access to the application programming interface (API) with the privileges of the built-in admin user, enabling them to view, modify, or disrupt the managed network infrastructure.

Cisco disclosed that it first became aware of active exploitation of CVE-2026-76504 in September 2026. The company has not shared details about the scale of attacks, the identity of the threat actors, or how many organizations have been compromised. However, it has released indicators of compromise (IoCs) to help defenders detect potential intrusions. Security teams should audit the file "/var/log/nms/containers/service-proxy/serviceproxy-access.log" for entries related to "j_security_check" originating from unknown or unauthorised IP addresses, and inspect "/var/log/nms/vmanage-server.log" for similar entries, paying particular attention to user names that begin with "viptela-reserved-". Any such log entries may indicate an attempted or successful exploitation.

Federal Civilian Executive Branch (FCEB) agencies in the United States have been given a deadline of October 3, 2026, to apply the necessary patches, in line with the binding operational directive that governs KEV entries. Security researchers have noted the pattern of Cisco SD-WAN products appearing on the list repeatedly. “Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited Vulnerabilities list, with eight 2026 CVEs landing on KEV this year alone – this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down,” said Jake Knott, head of threat intelligence at watchTowr, in a statement. He added that as a single-pane-of-glass tool used by enterprises to manage, configure, and monitor large networks, the platform is naturally an attractive target for adversaries.

Cisco has made fixed software releases available and urges all organisations running Catalyst SD-WAN Manager to upgrade immediately. In addition to patching, administrators should hunt for POST requests to any URL-encoded variants of "/j_security_check" and review access logs for signs of compromise. For businesses that rely on centralized network management systems, proactive infrastructure hardening is critical, and consulting with security-focused IT partners like AEU-I can help assess and strengthen defences against known threats before they are exploited.

While CVE-2026-76504 is a critical vulnerability in a specific enterprise product, the incident reinforces a universal lesson for website owners and IT teams: management interfaces of any kind, whether for networks, hosting panels, or cloud dashboards, must never be left exposed to the public internet without strong authentication and regular patching. Cisco’s advisory contains no workarounds that fully mitigate the risk, so upgrading to a patched version remains the only reliable remedy.

Come Proteggerti

  1. If your organization uses a Cisco Catalyst SD-WAN Manager device, update it immediately to the latest patched version provided by Cisco.
  2. Ask your managed IT or network service provider whether the SD-WAN software they manage for you has been patched and checked for any signs of unauthorized access.
  3. Review network logs for unusual logins or access attempts coming from unknown IP addresses, especially those targeting the web management interface.
  4. Restrict access to your network device management pages so they are only reachable from trusted internal networks, never directly from the open internet.
  5. Stay subscribed to vendor security advisories for any networking equipment you operate, and apply critical patches within days of release.

Vulnerabilità e Soluzioni

I Termini Spiegati

  • authentication bypass A security flaw that lets an attacker skip the normal login process and gain access without a valid username or password.
  • CVE A unique number assigned to a publicly known security vulnerability, making it easy to look up and discuss.
  • CVSS score A rating from 0 to 10 that shows how severe a security vulnerability is, with higher numbers meaning greater risk.
  • Known Exploited Vulnerabilities (KEV) A CISA-maintained list of security flaws that attackers are actually using right now, requiring urgent patching by US federal agencies.
  • API (Application Programming Interface) A set of rules that allows different software programs to talk to each other, often used to control or configure a device remotely.
  • indicators of compromise (IoCs) Tell-tale signs like specific log entries or file changes that suggest a computer or network has been broken into.

Servizi AEU correlati

  • AEU-I Consulenza IT e sicurezza