Cisco has disclosed an actively exploited authentication bypass in Catalyst SD-WAN Manager, its management platform for software-defined wide area networks (SD-WAN), that can give an unauthenticated remote attacker administrator access to the management application programming interface (API).
In an advisory published Sept. 30, 2026, Cisco rated the flaw 9.8 on the Common Vulnerability Scoring System (CVSS) 3.1 scale. It is tracked in the Common Vulnerabilities and Exposures (CVE) list as CVE-2026-76504.
The flaw stems from improper handling of encoded characters in HTTP requests, which lets a crafted request bypass an authentication rule protecting a specific API endpoint. Cisco said it affects Catalyst SD-WAN Manager regardless of system configuration, with internet-exposed systems at risk.
Cisco’s Product Security Incident Response Team (PSIRT) became aware of active exploitation in September. Cisco has not disclosed who is exploiting the flaw, how widely it has been used, or which organizations have been targeted.
In a post published Sept. 30 and updated Oct. 1, Rapid7 noted that the flaw follows two earlier critical unauthenticated flaws in Catalyst SD-WAN this year, CVE-2026-20127 and the Rapid7-discovered CVE-2026-20182, which affected a separate peering authentication service.
Fixed Releases and Cisco’s Log Checks
There is no workaround. Cisco has fixed the flaw in releases 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, and systems on releases earlier than 20.9 should migrate to a fixed release.
The cloud-based Cisco SD-WAN Cloud (Cisco Managed) service is fixed in release 20.15.605, and Cisco said no customer action is required there.
For on-premises deployments, Cisco recommended restricting access from unsecured networks and, where internet access is required, limiting it to known trusted hosts behind a filtering device. It described that mitigation as temporary and still recommended upgrading.
Rapid7 recommended upgrading on an emergency basis, outside normal patch cycles, and investigating internet-facing systems for compromise.
Cisco said defenders should review the service-proxy access log and vManage server log for requests to the j_security_check login endpoint involving an encoded character or usernames beginning with viptela-reserved-. It cautioned that these entries can also occur during normal operations, so they are investigation leads rather than proof of exploitation.
Customers seeking help assessing possible compromise can open a Severity 3 Technical Assistance Center (TAC) case referencing CVE-2026-76504, Cisco said.