CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

7 hours ago 6

Ravie LakshmananOct 01, 2026Vulnerability / Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation.

The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with the privileges of the admin user.

"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request," CISA said.

Cybersecurity

Successful exploitation could allow an attacker to sidestep authentication by sending a crafted HTTP request to the API of the affected system, and gain access to the API as the admin user.

The development comes after Cisco said it became aware of active exploitation of CVE-2026-76504 in September 2026. The networking equipment maker has made available indicators of compromise (IoCs) that customers can use to check if their environments are impacted -

Audit "/var/log/nms/containers/service-proxy/serviceproxy-access.log" for entries that are related to j_security_check from unknown or unauthorized IP addresses

Audit "/var/log/nms/vmanage-server.log" for entries that are related to j_security_check from unknown or unauthorized IP addresses, specifically being called for users that include names starting with "viptela-reserved-"

Cisco did not provide any details about the exploitation activity, who is behind it, how many organizations have been compromised thus far, or when the first instance of CVE-2026-76504 exploitation occurred. Federal Civilian Executive Branch (FCEB) agencies have time until October 3, 2026, to apply the fixes.

Cybersecurity

"Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited vulnerabilities list, with eight 2026 CVEs landing on KEV this year alone -- this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down," Jake Knott, head of threat intelligence at watchTowr, said in a statement.

"None of this should surprise anyone. As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it is naturally an attractive target."

Organizations running Catalyst SD-WAN Manager are advised to upgrade to a fixed release as soon as possible and follow vendor guidance to hunt for POST requests to any URL-encoded variants of "/j_security_check" and review instances for signs of exploitation.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Read Entire Article