SoftwareNews

Cisco SD-WAN zero-day: which releases fix CVE-2026-76504

The Cisco SD-WAN zero-day gives attackers admin API access. Which Catalyst SD-WAN Manager releases fix it, what to check, and the October 3 CISA deadline.

Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

Cisco logo sign with the company's blue bars and red lettering on a stone base outside its San Jose campus
Photo: Prayitno / Wikimedia Commons, CC BY 2.0

A Cisco SD-WAN zero-day, CVE-2026-76504, is being exploited against Catalyst SD-WAN Manager, the console that runs a company's whole SD-WAN fabric, and the fix is an upgrade to a fixed release such as 20.15.6.1, 20.18.4.1 or 26.2.1. Cisco disclosed it on September 30, 2026, CISA added it to its exploited list the same day, and US federal agencies have until Saturday, October 3, to act. Here's which release you need, how to look for signs of a break-in, and what to do if you can't upgrade this week.

Key takeaways

  • Confirmed exploited: Cisco says its security team learned of active exploitation in September 2026. The flaw scores 9.8 out of 10 and needs no password or user interaction.
  • Every on-premises Manager is affected, whatever its configuration, per Cisco. There is no workaround: only a fixed release closes it.
  • Fixed releases: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Anything older than 20.9 has to migrate to a fixed branch.
  • Cloud-hosted customers are already covered, according to Cisco and Rapid7.
  • The CISA deadline is October 3, 2026 for US federal civilian agencies, and it includes forensic triage, not only the patch.

What the Cisco SD-WAN zero-day does

Cisco's security advisory describes an authentication bypass in the way Catalyst SD-WAN Manager (formerly vManage) handles API login sessions. The Manager mishandles URI encoding, the percent-codes like %6a that stand in for characters in a web address, so a crafted HTTP request slips past a rule meant to protect one API endpoint. An unauthenticated attacker who can reach the Manager ends up with the privileges of the admin user.

That matters because of what the Manager controls. Field Effect's write-up on the exploitation notes that it holds routing policies, segmentation rules, device configurations and administrative accounts for every site in the network. Admin access there is access to the whole fabric.

Cisco classifies the bug as CWE-177, improper handling of URL encoding, and rates it 9.8 on CVSS 3.1. The advisory says it was found while resolving a Cisco Technical Assistance Center (TAC) support case.

Which releases fix CVE-2026-76504

Catalyst SD-WAN Manager releaseFirst fixed release
Earlier than 20.9Migrate to a fixed release
20.920.9.10.1
20.1220.12.8.2
20.1520.15.6.1
20.1820.18.4.1
26.126.1.2.1
26.226.2.1

Cisco's advisory lists release 20.15.605 for its cloud-hosted service, where it says the mitigation is already in place. Rapid7's analysis of CVE-2026-76504 reads that as no customer action required for Cisco SD-WAN Cloud (Managed), and urges on-premises customers to upgrade outside their normal patch cycle.

If you need to find vulnerable Managers across a large estate, Rapid7 says its scanners gained checks in the October 1 content release, and Qualys says its QID 317933 detects it.

Rows of black server racks filled with rack-mounted servers and status lights in a data center aisle
Photo: Victorgrigas / Wikimedia Commons, CC BY-SA 3.0

How to check for signs of compromise

Cisco's advisory points to two logs on the Manager:

  1. /var/log/nms/containers/service-proxy/serviceproxy-access.log: look for requests to j_security_check where a character is URI-encoded, such as POST /%6a_security_check (%6a is the letter "j"), especially from IP addresses you don't recognize.
  2. /var/log/nms/vmanage-server.log: look for entries with usernames that begin with viptela-reserved-.

BleepingComputer reports that Cisco recommends collecting admin-tech files and opening a TAC case so Cisco can judge whether a system was compromised. Do that before you upgrade if you can, so the evidence survives. Cisco's references also list Snort rule 67179 for network detection.

What to do if you can't patch yet

Cisco is clear that "there are no workarounds that address this vulnerability." What it offers is a mitigation for on-premises deployments: block access to the Manager from untrusted networks such as the internet, and keep the SD-WAN control components behind a filtering device like a firewall that only lets known, trusted hosts in. The Hacker News' report adds that the administrative ports 443, 22 and 830 should not be reachable directly from the internet.

That narrows who can try the attack. It doesn't fix the bug, and an attacker already inside your network can still reach the Manager. Treat it as a bridge to the upgrade, measured in days.

Why the October 3 deadline matters

CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on September 30. The catalog entry sets a due date of October 3, 2026, three days later, under Binding Operational Directive 26-04, and its required action includes CISA's forensic triage requirements alongside Cisco's fixes. Known ransomware use is listed as "Unknown" as of October 1.

The deadline legally binds only US federal civilian agencies, but a three-day window is a signal of how urgent CISA thinks this is for everyone running the product.

What happens next

This is not the first time this year. BleepingComputer counts CVE-2026-76504 as the fifth actively exploited SD-WAN zero-day of 2026, after CVE-2026-20127, CVE-2026-20182, CVE-2026-20245 and CVE-2026-20262. Cisco has not said who is behind the attacks or how many systems were hit, as of October 1. Watch the advisory for updated indicators.

It's been a heavy week for emergency fixes: Apple patched an exploited CoreGraphics zero-day, and DIVD disclosed how an AI agent chained Zammad zero-days to breach its systems. If you run edge appliances, our guide to the NetScaler zero-days follows the same check, patch and clean-up order.

Bottom line

If you run Catalyst SD-WAN Manager on premises, this Cisco SD-WAN zero-day is confirmed exploited by Cisco and CISA. Upgrade to the fixed release for your branch now, and check the two logs for encoded j_security_check requests and viptela-reserved- users before you do. If the upgrade has to wait, take the Manager off the internet and limit it to trusted hosts. Cloud-hosted customers are covered, according to Cisco. Federal agencies have until October 3.

FAQ

Is CVE-2026-76504 being exploited?

Yes. Cisco says its Product Security Incident Response Team became aware of active exploitation in September 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 30. Neither has said how widespread the attacks are.

Is there a workaround for the SD-WAN Manager flaw?

No. Cisco's advisory says no workaround addresses it. Restricting access to the Manager from the internet and putting it behind a firewall reduces the risk, but only a fixed release removes the flaw.

Do cloud-hosted SD-WAN Manager customers need to do anything?

According to Cisco, the mitigation is already deployed in its cloud-hosted environment, and Rapid7 says no customer action is required there. The upgrades in the table apply to on-premises Managers.

What if my Manager runs a release older than 20.9?

Cisco doesn't list a fix for releases before 20.9. Its advisory says to migrate to a fixed release, such as one of the branches in the table above.

Filed under Software

Newsletter

New articles, in your inbox.

Free. Unsubscribe in one click. Your email is kept by beehiiv, our newsletter service, and used only for this newsletter.