Cisco has issued an advisory regarding a critical vulnerability in Cisco Catalyst SD-WAN Manager, which could allow unauthenticated remote access.
According to the advisory, “an attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.”
The vulnerability, which carries a critical score of 9.8 is being tracked as CVE-2026-76504. It has been fixed in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605 with no user action required. However, customers running 26.2, 26.1, 20.18, 20.15, and 20.12 need to upgrade to the patched version of their respective release. Users of release 20.9 and earlier need to migrate to a fixed release.
Customers are encouraged to monitor the following log files for suspicious activity:
- serviceproxy-access.log — Audit for entries related to j_security_check from unknown or unauthorized IP addresses.
- vmanage-server.log — Audit for entries related to j_security_check from unknown or unauthorized IP addresses, specifically being called for users that include names starting with viptela-reserved-.
Learn more at Cisco.