Cisco SD-WAN Manager admin bypass is on the KEV list
CVE-2026-76504, no workaround

Cisco SD-WAN Manager admin bypass is on the KEV list

Cisco Catalyst SD-WAN Manager has an unauthenticated admin-API bypass, and there is no workaround.

What happened

Advisory cisco-sa-sdwan-webauth-xr8beuuU covers CVE-2026-76504. A crafted HTTP request can get past the API session check because URI encoding is handled badly. The caller reaches the admin API without authenticating. Cisco rates it CVSS 9.8. Cisco says there are no workarounds.

The original brief also recorded a CISA Known Exploited Vulnerabilities due date of 3 October 2026. Patching does not answer whether the API was already used.

Who is affected

  • Cisco Catalyst SD-WAN Manager, regardless of configuration
  • Releases earlier than 20.9 must move to a fixed release
  • Cisco-managed SD-WAN Cloud release 20.15.605 is already addressed. No user action is required there

What to do now

  • Upgrade to a fixed train: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1.
  • If the manager is reachable, check logs for unexpected admin API access. Cisco's indicator example is a URI-encoded character in the request, not only the sample %6a.

Source: Cisco advisory cisco-sa-sdwan-webauth-xr8beuuU

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Attackers are getting more from AI than defenders
Weaponization is now under 24 hours