Attackers have been exploiting a critical security flaw in Cisco Catalyst SD-WAN Manager that allows them to bypass authentication and gain administrative access to the platform's API without needing any credentials. The vulnerability, which Cisco has now patched, stems from improper handling of URI encoding in HTTP requests and affects software used to configure and operate software-defined network deployments across thousands of devices. The company disclosed the zero-day exploit in a security advisory after attackers had already begun using it in the wild.
The vulnerability, designated CVE-2026-76504, carries a critical severity rating of 9.8 on the CVSS scale. The flaw affects customers running SD-WAN Manager software releases 20.9 and earlier, 20.12, 20.15, 20.18, 26.1, and 26.2, all of which require upgrades to their respective patched versions. While Cisco has already addressed the issue in its cloud-managed SD-WAN service, customers hosting affected software on-premises must manually apply updates. The bug can be exploited remotely through a crafted HTTP request without requiring user interaction, and Cisco says there's no workaround—only mitigation through restricted network access until patches can be deployed. According to Cisco's official documentation, SD-WAN Manager clusters can support thousands of devices, with some configurations scaling to as many as 12,500 devices.
"The barrier to exploitation is very low once the management interface is reachable," said Sakshi Grover, IDC's research director for information and data security. The company has provided specific indicators organizations can use to detect whether they've been targeted, including examining "serviceproxy-access.log" files for requests to the "j_security_check" endpoint from unknown IP addresses. One telltale sign involves URI encoding, where attackers represent the character "j" as "%6a" in their requests. Cisco also recommends checking for encoded requests involving usernames beginning with "viptela-reserved-," which are reserved system service accounts that shouldn't appear in normal authentication attempts.
The severity extends well beyond simple unauthorized access because compromising the management layer gives attackers far more control than breaching an individual edge device. Grover noted that administrative API access could potentially allow an attacker to understand network topology, modify templates or policies, weaken segmentation, establish persistence, or distribute unauthorized configuration changes across multiple locations. While every configuration is vulnerable, practical exposure varies significantly—an internet-accessible management interface presents much more immediate risk than one isolated within a tightly controlled administrative network. This distinction matters because attackers gaining control of a single management server could potentially manipulate configurations across thousands of connected devices simultaneously, turning a single vulnerability into a network-wide compromise.
Cisco is urging customers to upgrade all affected SD-WAN Manager instances to fixed releases immediately and submit admin-tech files from every node—including cluster members and disaster-recovery deployments—to its Technical Assistance Centre for analysis. The company recommends not waiting for the analysis results before patching, emphasizing that organizations should upgrade first and then have TAC assess collected data for indicators of compromise. Grover advised that credentials, tokens, keys, and certificates should be rotated wherever investigation suggests they may have been accessed or modified, warning that "patching closes the vulnerability, but it does not remove persistence or reverse configuration changes that an attacker may already have made." She emphasized that while a CVSS 9.8 score tells a board that a flaw is severe, it doesn't convey that the exposure may encompass the entire WAN. Organizations managing distributed networks through centralized platforms face an inherent trade-off between operational efficiency and concentrated risk—efficiency that makes administration scalable also makes a single successful attack devastatingly broad in its reach.

