Security & Risk5 minNewsroom

Cisco Confirms CVE-2026-76504 SD-WAN Manager Exploit

CVE-2026-76504 allows unauthenticated attackers to gain admin API access to Catalyst SD-WAN Manager. Cisco reports no workaround, and CISA added the exploit to the active catalog.

Aparelho de rede em rack com cabos conectados em um corredor de data center.

Cisco issued a security alert on Wednesday (30) for CVE-2026-76504, an authentication bypass vulnerability in the API of the Catalyst SD-WAN Manager, stating that the vulnerability is currently being exploited. The severity score is 9.8 out of 10 on the CVSS 3.1 scale. On the same day, the CISA, the U.S. cybersecurity agency, included the vulnerability in its catalog of actively exploited vulnerabilities, known as KEV.

According to the manufacturer’s notice, an unauthenticated remote attacker can send a crafted HTTP request and gain access to the API with administrative privileges. The cause is improper handling of URL-encoded characters, classified as CWE-177. Cisco states that the problem affects the product regardless of configuration, and there is no workaround: the only solution is to upgrade.

Why the SD-WAN Manager is a Top Target

The SD-WAN Manager, formerly vManage, is the control panel that defines routing policies, segmentation, and encryption for an entire company's branch network. Controlling the API effectively controls how bank branches, stores, and factories communicate with each other and with the cloud. Administrative access there allows altering routes, rerouting traffic, or distributing configurations to hundreds of edge routers at once.

This is the second time in a few days that edge devices from major vendors have made the CISA's list. On September 27, the agency included two critical vulnerabilities from Citrix NetScaler, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on the CVSS 4.0 scale, exploited as zero-days against government agencies and financial institutions, according to reports from researchers at Rapid7 and Unit 42. The pattern is the same: the attacker targets the equipment exposed to the internet that rarely runs detection tools.

Cisco reported that its response team, PSIRT, became aware of the exploitation in September but did not disclose how many customers were affected nor attributed the campaign to a specific group.

What Changes for the CISO

For the 20.x lines, the patched versions are 20.9.10.1, 20.12.8.2, 20.15.6.1, and 20.18.4.1, according to Cisco's notice. Those running versions prior to 20.9 must migrate to a supported version train, which turns a patch into a project. Until the upgrade, Cisco recommends restricting access from untrusted networks, allowing only known hosts, and placing SD-WAN control components behind a firewall.

Inclusion in KEV triggers BOD 22-01, which requires U.S. federal civilian agencies to patch the vulnerability within a short time frame or shut down the product. This rule only applies to the U.S. government, but cyber risk insurers and auditors often use the catalog as a measure to determine if a private company acted diligently after an incident.

Where Risk Lies Outside the U.S.

In the European Union, the NIS2 directive requires essential and important entities to send an initial alert to the national authority within 24 hours of becoming aware of a significant incident, with fines reaching 10 million euros or 2% of global revenue for essential entities. For a German bank or a Spanish energy operator using Cisco SD-WAN, discovering late that the panel was compromised is no longer just a technical problem; it becomes a regulatory exposure.

In India, where delivery centers of TCS, Infosys, Wipro, and dozens of global captives operate networks for American and European clients via managed connections, the vulnerability lands on the desk of those managing third-party infrastructure. CERT-In's rule, in effect since 2022, mandates the notification of cyber incidents within six hours. A provider managing the SD-WAN for multiple clients in the same environment may have to respond to regulators in three jurisdictions for the same event.

In Brazil, banks and retailers with large agency and store networks are typical users of the technology. Resolution 4,893 from the Monetary Council requires financial institutions to notify the Central Bank of significant incidents, and the LGPD imposes fines of up to 2% of revenue in Brazil, capped at R$ 50 million per infraction, for personal data breaches.

The absence of a workaround is the most concerning factor. In previous edge device vulnerabilities, disabling an interface or service bought time to plan a maintenance window. This time, the only time available is what the company can create by closing access to the panel.

Sources

  1. cisa.govhttps://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog
  2. sec.cloudapps.cisco.comhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v
  3. rapid7.comhttps://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504/
  4. thehackernews.comhttps://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk →