Cisco Warns of Actively Exploited Authentication Bypass in SD-WAN Manager

Internet-edge firewalls and VPN gateways monitored in a security operations center

Written by

in

Cisco has released fixes for an actively exploited vulnerability in Catalyst SD-WAN Manager. Tracked as CVE-2026-76504, the critical flaw can allow an unauthenticated remote attacker to bypass an API authentication check and interact with the management system as the administrative user.

Crafted requests can cross the management boundary

Cisco says the issue results from improper handling of URI encoding in an HTTP request. An attacker able to reach the Manager API can send a crafted request that bypasses the intended restriction. The default administrative role can perform all operations, so successful exploitation creates a high-impact management-plane risk. Cisco reported awareness of active exploitation but did not disclose the number of affected organizations or describe the observed post-compromise activity.

Upgrade and review access logs

Fixed releases are available and Cisco says there is no workaround. Operators should upgrade according to the affected release train, restrict management access to trusted hosts and inspect the log locations identified in the advisory for unusual encoded login requests. Patch deployment should be paired with compromise assessment because an update does not by itself establish that prior unauthorized access did not occur. SectechMedia’s guide to network segmentation verification explains how management-plane exposure can be tested and reduced.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *