A critical authentication bypass in Cisco Catalyst SD-WAN Manager is under active exploitation, and federal agencies have already had to patch it.
The Hacker News reports that CVE-2026-76504, a critical authentication bypass in Cisco Catalyst SD-WAN Manager rated 9.8 on the CVSS scale, is being actively exploited. A hex encoding flaw in how the product handles URI encoding in HTTP requests lets an unauthenticated remote attacker sidestep authentication and reach the system's API with admin-level privileges. Cisco's PSIRT became aware of active exploitation in September 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, giving federal civilian agencies until October 3 to patch.
Cisco has published fixed releases across multiple trains, including 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Defenders can check exposure by auditing service-proxy and vManage server logs for j_security_check entries from unknown IPs, particularly ones tied to usernames starting with "viptela-reserved-".
Why it matters: SD-WAN controllers sit at the center of enterprise network traffic and policy, admin-level compromise there can cascade into every site the controller manages. Patch on the vendor's timeline, treat the published log indicators as a hunting checklist, and keep management interfaces off the open internet.