(TLP:CLEAR) Vulnerability Notification – Cisco SD-WAN Manager Actively Exploited
Created: Thursday, October 1, 2026 - 15:01
Categories: Cybersecurity, Security Preparedness
ACTION MAY BE REQUIRED for utilities using Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Summary: A critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager is being actively exploited in the wild. Tracked as CVE-2026-76504 (CVSS 9.8), the vulnerability is in the Manager’s API session-based authentication mechanism. Successful exploitation could allow a remote, unauthenticated attacker to access the API as the admin user. All deployments are affected regardless of configuration, and no workarounds exist. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 30. It is the eighth Cisco SD-WAN vulnerability added to the catalog this year.
Analyst Note: SD-WAN Manager is the central console for managing and configuring wide area networks, which makes it an attractive target. A compromise could give attackers control over the network, potentially enabling lateral movement or access to systems supporting OT environments. Cisco-managed SD-WAN deployments have already been patched.
Affected Versions (fixed release):
- 26.2 (26.2.1)
- 26.1 (26.1.2.1)
- 20.18 (20.18.4.1)
- 20.15 (20.15.6.1)
- 20.12 (20.12.8.2)
- 20.9 (20.9.10.1)
- Earlier than 20.9 (migrate to a fixed release)
WaterISAC strongly encourages members to review Cisco’s advisory and take the following actions:
- Upgrade affected systems to a fixed release immediately.
- If possible, hunt for POST requests to URL-encoded variants of “/j_security_check” and review Cisco’s indicators of compromise.
- Review instances for signs of prior exploitation. One option is to open a Severity 3 Cisco TAC case with CVE-2026-76504 in the title.
Additional Reading
- Cisco Security Advisory: Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)
- Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
- New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 10.2, 11, 12
