Cisco Urges Immediate Upgrades After Critical SD-WAN Flaw Active Exploitation

Cisco recommends checking serviceproxy-access.log and vmanage-server.log for possible signs of compromise, including suspicious j_security_check requests from unknown addresses and requests involving usernames beginning with “viptela-reserved-”; a search for one literal encoded string alone may miss activity.
Cisco says its responders learned of the exploitation in September 2026 after a customer support case was raised; the company has not publicly described attackers’ follow-on activity or the scale of the attacks.
The advisory’s encoded “j” in j_security_check is only an example: Cisco says any single URI-encoded character may trigger the authentication bypass.
Cisco’s listed fixed releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; Cisco SD-WAN Cloud (Cisco Managed) release 20.15.605 already includes the fix, with no customer action required.
Cisco is warning that hackers are actively exploiting CVE-2026-76504, a critical flaw in Catalyst SD-WAN Manager that lets attackers bypass authentication and gain full administrator access without a password ISSSource. The vulnerability, rated 9.8 out of 10 in severity, stems from improper handling of web address characters in API requests and affects all system configurations dev.to. Cisco has released software fixes and is urging customers to upgrade immediately, though the company has not disclosed who is behind the attacks or how many systems have been compromised.
The vulnerability exploits how the SD-WAN Manager handles URI-encoded characters — special symbols in web addresses used to bypass security checks. An attacker can send a specially crafted request to the API without logging in and gain full admin privileges cyberpress.org. The flaw affects all versions regardless of how the system is configured, meaning even locked-down deployments are at risk dev.to.
Cisco has released software updates to address the flaw. Fixed versions include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1 dev.to. Cloud-hosted customers using Cisco Managed SD-WAN are already protected, as release 20.15.605 includes the fix with no action needed. For on-premises systems, Cisco recommends restricting access to trusted networks only and placing security components behind a firewall to limit exposure realhacker.news.
Organizations should check system logs immediately for evidence of compromise. Look for suspicious requests to 'j_security_check' from unknown addresses and any requests using usernames beginning with 'viptela-reserved-' helpnetsecurity.com. Cisco warns that searching for just one encoded character may miss attacker activity. Cisco learned of active exploitation in September 2026 after a customer reported suspicious activity, but has not detailed the scope of attacks.
This marks the fifth time in 2026 that Cisco has disclosed active zero-day attacks against its products helpnetsecurity.com. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, flagging it as a threat actively targeted by criminals. The rapid succession of critical flaws in Cisco's network products underscores the growing risk facing organizations that depend on the company's SD-WAN technology for their core network operations.
Publishers
15
Articles
9
Reach
24