← All news
Vulnerability ManagementThreat IntelligenceIncident Response

Cisco Says Attackers Were Already Exploiting a CVSS 9.8 Login Bypass in SD-WAN Manager Before the Patch Existed, and There Is No Workaround

Obiguard Research Team·October 10, 2026·4 min read

Cisco has disclosed an actively exploited authentication bypass in Catalyst SD-WAN Manager, the controller formerly known as vManage, and says there is no workaround. The flaw, tracked as CVE-2026-76504 and rated CVSS 9.8, let attackers reach the management API as the admin user with a single crafted HTTP request. Cisco's advisory was published on 30 September, and according to iTnews and a Cloud Security Alliance research note, Cisco's PSIRT learned of exploitation in September, before updates were available.

What the flaw is

The bug sits in the API's session-based authentication. Cisco attributes it to improper handling of URI encoding, and the CSA note gives %6a standing in for the "j" in the j_security_check path as an illustration (CSA describes that mechanism as its own interpretation, not a Cisco finding). An unauthenticated remote attacker needs no credentials and no user interaction. Cisco says it applies regardless of system configuration. It said the bug was found while resolving a support case.

What is not known

  • Who is exploiting it. No attribution had been published as of 2 October.
  • How many customers are affected, or exactly when attacks began.
  • The number of related zero-days. Outlets differ on how many SD-WAN CVEs and Cisco zero-days this makes in 2026, so treat any single tally with caution.

The flaw is separate from CVE-2026-20182, fixed in May, and from CVE-2026-20245 and CVE-2026-20262, fixed in June. CSA reports that CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on 30 September with a federal deadline of 3 October.

Fixed releases

Release train Fixed in
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

Anything earlier than 20.9 has to migrate to a fixed release. Cisco lists no workaround. Keeping on-premises Manager instances off the internet, or limiting access to known trusted hosts behind a firewall, reduces exposure but is only a stopgap.

What to hunt for

Per iTnews and CSA, Cisco's guidance is to audit two logs:

  • serviceproxy-access.log for URL-encoded variants of /j_security_check, especially POST requests from unfamiliar addresses.
  • vmanage-server.log for entries referencing usernames that begin with viptela-reserved-.

Two cautions. Searching for one literal string is a weak test, because any single character in the path can be encoded. And some of these indicators can appear in normal operation, so compare results with your baseline before declaring a compromise. If you suspect one, Cisco asks for a Severity 3 TAC case with the CVE in the title, opened after running request admin-tech.

Why this one matters

SD-WAN Manager is a control plane. Whoever holds admin API access to it can reconfigure how branch offices, data centres and cloud networks connect. That makes it a high-value target, and the pattern is familiar: our coverage of the FortiMail zero-day described the same shape, a critical edge or management system exploited before a fix was ready. When the patch is late or missing, detection is the only control you have.

Where Obiguard SOC fits

For a bug like this, the useful question is not "are we patched yet" but "did anyone log in the wrong way in the weeks before we patched." The evidence is spread across proxy logs, application logs and the admin accounts that were created or used afterwards. Obiguard SOC is built to collect that kind of telemetry in one place, apply detections such as unusual encoded authentication requests and unexpected admin activity, and give an analyst a timeline to review rather than raw logs from several appliances.

It will not patch Manager for you, and it cannot see a log source that was never forwarded. What it does is shorten the gap between exploitation and someone noticing, and make the retrospective check after a zero-day a query instead of a scramble.

The question to take away

If your SD-WAN Manager was reached with an encoded login request last month, which log would show it, and would anyone have been looking at it?

See how Obiguard SOC works or talk to us about monitoring your network management plane.

How Obiguard helps

Turn this into enforced policy, not just awareness.

Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.

See how it works →