INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco SD-WAN Manager Vulnerable to Critical Authentication Bypass

| 2026-09-30 14:46 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A critical vulnerability has been identified in Cisco SD-WAN Cloud-Pro and Cisco SD-WAN for Government, two deployment types previously mentioned. The flaw, CVE-2026-76504, allows a remote attacker with no login access to use the Manager's API as an admin user, carrying a CVSS score of 9.8 out of 10. This vulnerability affects multiple release trains, including 20.15 and later versions, but is already fixed in release 20.15.605 for Cisco SD-WAN Cloud (Cisco Managed). Customers on affected releases are advised to open a Severity 3 case with Cisco TAC and include CVE-2026-76504 in the title to help determine whether their Manager has been compromised.
Technical Mitigations AI-generated
• Restrict access to the SD-WAN Manager from unsecured networks such as the internet. • Only allow known, trusted hosts in when internet access is required and sit control components behind a firewall. • For on-prem Managers exposed to the internet, restrict access to it.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

se•••••.log
vm•••••.log
20.15.•••.•••
20.9.•••.•••
20.12.•••.•••
20.18.•••.•••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-76504CVE-2026-76504 CVE-2026-20262CVE-2026-20262 CVE-2026-20127CVE-2026-20127 CVE-2026-20182CVE-2026-20182 CVE-2026-20245CVE-2026-20245
Target & Sectors
Global Scope
Incident Timeline
‎November 2021
Threat actors have exploited 90 Cisco vulnerabilities, including four in Cisco Catalyst SD-WAN Manager and seven associated with ransomware operations, since November 2021.
tactic Ransomware
general_metric 90 Cisco vulnerabilities
‎at least 2023
Threat actors exploited a maximum-severity Catalyst SD-WAN Controller auth bypass flaw (CVE-2026-20182) since at least 2023, while Cisco patched an SD-WAN Manager information disclosure security flaw (CVE-2026-20127).
vulnerability CVE-2026-20182
vulnerability CVE-2026-20127
organisation Catalyst SD-WAN Controller
‎September 2026
The Cisco Product Security Incident Response Team became aware of active exploitation of a vulnerability in its SD-WAN product in September 2026.
organisation Product Security Incident Response Team
‎September 30
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager.
organisation Cisco SD-WAN
organisation Cisco
tactic T1588.006 - Vulnerabilities
‎2026/09/30
Threat actors exploited CVE-2026-76504, a vulnerability in T1588.006 protocol, to target U.S. federal agencies.
vulnerability CVE-2026-76504
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
attribution KEV
‎2026/09/30
Threat actors are actively exploiting CVE-2026-76504, a critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager's API session-based authentication management.
organisation API
organisation CVE-2026-76504
infrastructure 20.9
infrastructure 20.9.10
infrastructure 20.12
infrastructure 20.12.8
infrastructure 20.15
infrastructure 20.15.6
infrastructure 20.18
infrastructure 20.18.4
infrastructure 26.1
infrastructure 26.1.2
infrastructure 26.2
infrastructure 26.2.1
organisation Cisco TAC
organisation CVSS
organisation Cisco Catalyst SD-
organisation Migrate
infrastructure 20.10
infrastructure 20.11
infrastructure 20.13
infrastructure 20.14
infrastructure 20.16
infrastructure 20.15.605
organisation Cisco SD-WAN Cloud
organisation IP
organisation SD-WAN
organisation Technical Assistance Center
organisation TAC
organisation SD-WAN vManage
organisation Catalyst SD-WAN
infrastructure 6,000 WAN devices
organisation Cisco Catalyst SD-WAN
organisation the Cisco TAC
organisation NFL
organisation CHANEL
‎Saturday, October 3
Threat actors exploited CVE-2026-76504, a vulnerability in T1588.006 protocol, to target U.S. federal agencies.
vulnerability CVE-2026-76504
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
attribution KEV
Tactical Metrics
Metrics
infrastructure
‎20.9
Software Version
Metrics
infrastructure
‎20.9.10
Software Version
Metrics
infrastructure
‎20.12
Software Version
Metrics
infrastructure
‎20.12.8
Software Version
Metrics
infrastructure
‎20.15
Software Version
Metrics
infrastructure
‎20.15.6
Software Version
Metrics
infrastructure
‎20.18
Software Version
Metrics
infrastructure
‎20.18.4
Software Version
Metrics
infrastructure
‎26.1
Software Version
Metrics
infrastructure
‎26.1.2
Software Version
Metrics
infrastructure
‎26.2
Software Version
Metrics
infrastructure
‎26.2.1
Software Version
Metrics
infrastructure
‎20.10
Software Version
Metrics
infrastructure
‎20.11
Software Version
Metrics
infrastructure
‎20.13
Software Version
Metrics
infrastructure
‎20.14
Software Version
Metrics
infrastructure
‎20.16
Software Version
Metrics
infrastructure
‎20.15.605
Software Version
Metrics
infrastructure
6,000
Wan Devices
Intelligence Sources
BleepingComputer 2026-09-30
Mastodon BleepingComputer 2026-09-30