What Happened
Cisco disclosed CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager, formerly known as vManage. The flaw comes from improper handling of URI encoding in an HTTP request. An unauthenticated attacker sends a specially built request to the API and lands on the system with administrator privileges. Attackers place a URI-encoded character in the request to slip past the authentication rule. Cisco confirms active exploitation, and the flaw affects every deployment regardless of configuration.
Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Customers on releases earlier than 20.9 must migrate to a fixed train. BleepingComputer has the full report.
Why This Matters for Canadian Organizations
SD-WAN Manager is the control plane for the whole network. A single Manager handles up to 6,000 devices. An attacker with administrator access changes routing policy, pushes configuration to every site, and watches traffic between branches.
Canadian banks, retailers with national store networks, provincial health authorities, school boards, and municipalities all use SD-WAN to link sites. For federally regulated financial institutions, OSFI Guideline B-13 expects timely vulnerability management and quick escalation of material incidents. If personal information crosses a compromised network, PIPEDA breach reporting duties apply once a real risk of significant harm exists. This is the latest in a run of actively exploited Cisco SD-WAN flaws this year, so your team already knows the drill. Run it again today.
What to Do
Patch to a fixed release first. Next, search serviceproxy-access.log and vmanage-server.log for j_security_check entries from unauthorized IP addresses. Collect admin-tech files and open a case with Cisco TAC for a compromise assessment if you find anything odd. Limit access to the Manager interface to dedicated management networks. Review administrator accounts, API keys, and recent configuration templates for changes you did not make.
See more technical breakdowns in our TechTalk section and daily updates in News.






