1. Home
  2. Resources
  3. News
  4. Cisco SD-WAN Zero-Day (CVE-2026-76504): What…

Cisco SD-WAN Zero-Day (CVE-2026-76504): What IT Leaders Should Do Now

INVITE engineer in a client conversation about network security

TL;DR: CVE-2026-76504 is an actively exploited Cisco SD-WAN zero-day that lets an unauthenticated attacker reach the Catalyst SD-WAN Manager API as an admin, and the only fix is upgrading to a patched release. INVITE treats this as a two-step job: patch the manager, then check its logs for signs someone got in first. This guide is for IT Directors and security leaders at mid-market and enterprise organizations running Cisco Catalyst SD-WAN.

On September 30, Cisco confirmed attackers are exploiting a critical authentication bypass in Catalyst SD-WAN Manager, the console formerly known as vManage. The same day, CISA added it to the Known Exploited Vulnerabilities catalog and gave federal agencies until October 3 to patch and complete a compromise assessment. That second requirement is the one most teams skip.

What Is CVE-2026-76504?

CVE-2026-76504 is a CVSS 9.8 authentication bypass in the Cisco Catalyst SD-WAN Manager API. The software mishandles URI encoding in HTTP requests, so a crafted request slips past the rule meant to restrict a protected API endpoint. A successful exploit gives a remote, unauthenticated attacker admin-level API access to the system that configures and monitors your entire SD-WAN fabric.

Cisco says the flaw affects every deployment regardless of configuration, and there are no workarounds.

Which Cisco SD-WAN Releases Are Affected?

Every supported train is affected. Upgrade to the first fixed release for your version:

Catalyst SD-WAN Manager Release First Fixed Release
Earlier than 20.9Migrate to a fixed release
20.920.9.10.1
20.1220.12.8.2
20.1520.15.6.1
20.1820.18.4.1
26.126.1.2.1
26.226.2.1

Cisco Meraki SD-WAN is a separate, cloud-managed platform and is not named in this advisory. If you run both, confirm which product manages each site before you assume you are clear.

How Do You Know If Your SD-WAN Manager Was Compromised?

Check the logs before and after you patch. Cisco’s indicators of compromise point to two files:

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log: look for j_security_check entries from unknown or unauthorized IP addresses.
  • /var/log/nms/vmanage-server.log: look for j_security_check entries, especially for usernames beginning with “viptela-reserved-“.

Attackers have been URI-encoding the letter “j” as %6a, so hunt for POST requests to encoded variants of /j_security_check. Collect admin-tech files and a device snapshot first; patching without preserving evidence can erase the trail you need.

Why Does Cisco SD-WAN Keep Landing on CISA’s KEV List?

This is the fifth actively exploited Cisco SD-WAN zero-day of 2026, following CVE-2026-20127 in February, CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in June. SD-WAN Manager controls the whole wide area network, so one compromise lets an attacker change routing and policy at every branch. Protect it like a domain controller.

What Should IT Teams Do This Week?

  1. Inventory. Identify every Catalyst SD-WAN Manager instance, on-premises and cloud-hosted, and its release.
  2. Preserve evidence. Pull admin-tech files and log snapshots before changing anything.
  3. Upgrade. Move to the fixed release in the table above. Versions before 20.9 need a migration plan now.
  4. Restrict access. Remove internet exposure of the management interface and allow only known, trusted hosts.
  5. Hunt and monitor. Review the log indicators, rotate admin credentials, and feed SD-WAN Manager logs into your SOC or MDR provider going forward.

The SonicWall SMA 1000 zero-days followed the same pattern last month. As a certified Cisco partner with CCNA and CCNP engineers, INVITE has managed Cisco environments across Salt Lake City, Phoenix, and the Mountain West for more than a decade.

Frequently Asked Questions

Is there a workaround for CVE-2026-76504?

No. Cisco states there are no workarounds. Restricting management access to trusted hosts reduces exposure, but upgrading to a fixed release is the only remediation.

Does CVE-2026-76504 affect Cisco Meraki SD-WAN?

The advisory covers Cisco Catalyst SD-WAN Manager (formerly vManage). Meraki SD-WAN is a separate cloud-managed platform and is not listed.

What is the CISA deadline for CVE-2026-76504?

CISA ordered federal civilian agencies to patch and perform a compromise assessment by October 3, 2026. Private organizations should treat that date as a benchmark.

Should we bring in outside help to check for compromise?

If your team lacks SD-WAN forensics experience or log retention, yes. Cisco TAC can assist, and a partner can run the upgrade and the hunt in parallel.

Get a Cisco SD-WAN Compromise Check

Read Cisco’s security advisory and CISA’s KEV catalog entry, then schedule a Cisco SD-WAN compromise check with INVITE’s certified engineers. We will confirm your exposure, preserve the evidence, and get you patched.