An SD-WAN manager is the one place that knows how to log in to every branch router. Cisco says an unauthenticated attacker can now call its admin API. CVE-2026-76504 is an authentication bypass in Cisco Catalyst SD-WAN Manager rated 9.8. Cisco says it is being actively exploited, there is no workaround, and CISA added it to the Known Exploited Vulnerabilities catalog on 30 September, with a federal remediation date of 3 October.
Updating closes the hole. It does not tell you whether the manager was read or changed while it was open, and the manager is full of material worth reading.
What is confirmed
According to Cisco as relayed by Rapid7 and watchTowr, the flaw is improper handling of URL encoding (CWE-177) in the manager's API session authentication. A crafted HTTP request containing a URI-encoded character in the login-handler path makes the authentication rule fail to match, so the request reaches the protected endpoint without credentials and with the privileges of the admin user. Cisco says it learned of exploitation in September, and no workaround exists. The fixed releases it lists are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. watchTowr adds that releases before 20.9 are affected and that Cisco-managed cloud instances are patched by Cisco. Check your own train against Cisco's advisory, not this summary.
Rapid7 lists indicators to look for in logs: requests to the login-check path from sources you do not recognise, URL-encoded variants of that path, and usernames beginning with viptela-reserved- in the manager's own logs. watchTowr suggests reviewing the proxy and manager server logs for unauthorised logins and restricting network access to the manager while you upgrade.
What is not known
No source we reviewed names an actor, a campaign or a victim, and none says what attackers did once they had admin API access. watchTowr says it is unclear whether it reproduced the flaw independently, and that it has no details on lateral movement or data theft. “Exploited in the wild” means someone is using it, not that every exposed manager was breached. Cisco's advisory is also silent, in the material we read, on rotating credentials or certificates afterwards, so the rotation advice here is ours.
Why the manager is a credentials problem
With admin API access, the sources say an attacker can view or change the configuration of every device the manager controls, and Rapid7 lists device inventory and topology, system configuration, configuration templates, and stored credentials and certificates as within reach. watchTowr notes that the default admin account holds the unrestricted network administrator role.
Think about what a template or a device configuration contains in practice: SNMP strings, RADIUS or TACACS shared secrets, local administrator accounts, routing authentication keys, VPN pre-shared keys, certificates and the controller trust material that lets devices enrol. Which of those exist in your deployment depends on how you built it, and that is exactly the inventory to make before deciding what to rotate.
The second risk is write access rather than read access. Someone with admin API rights could add an administrator, alter a template or push a configuration to the fleet. An upgrade removes the way in; it does not remove what was left behind.
A response order
- Reduce exposure now. Restrict internet access to the manager and allow only known hosts, as the sources suggest, while you arrange the upgrade.
- Collect logs before the maintenance window. Pull the manager and proxy logs and look for the indicators above. If you find them, open a case with Cisco TAC, which the sources recommend, and keep the evidence.
- Upgrade to a fixed release for your train. Cisco calls for patching outside normal cycles. If you are on a release older than 20.9, plan a move to a supported train, since watchTowr says those releases are affected.
- Audit the manager's own state. Review the user list, API keys, templates and recent configuration pushes for changes nobody on your team made, and remove any administrator you cannot account for.
- Rotate by dependency, starting where one value protects the most. Manager admin and API credentials first, then the AAA and SNMP secrets in your templates, then routing and VPN keys. Treat certificate and controller trust changes as a planned operation with Cisco guidance, because a careless re-enrolment can take branches offline.
- Use the rotation to shrink the problem. If device credentials are shared across the whole fleet, take the opportunity to make them per-site or centrally authenticated, so the next exposure does not reach everything.
- Record what you could not verify. If the logs are incomplete, say so rather than resolving it optimistically.
The handover that causes the second incident
An SD-WAN rotation is not one engineer typing one password. New AAA secrets, VPN keys and local accounts have to reach the network engineers and sometimes the carriers or managed service providers who configure sites. Under pressure these get pasted into the incident channel or emailed in a spreadsheet, where they stay long after the incident closes.
Plan the delivery path first. Send each value once, to the person who needs it, over a channel that does not keep it, and send the heads-up that it is waiting separately. Keep secrets out of the incident ticket. For the highest-value values, such as the break-glass administrator credential, require more than one person to reconstruct them.
Where Secretus fits, and where it does not
Secretus covers the human handover step: an authorised person sending a short text secret that is encrypted in the browser, over a link that stops working after the expiry you set or the first successful open. Team Split can require several holders to reconstruct a high-value text secret.
It is not a network management tool or a certificate authority. It cannot patch the manager, audit templates, rotate a RADIUS secret on your devices or tell you whether CVE-2026-76504 was used against you. Do those with Cisco's tooling and your own process, and use a one-time channel for the moment one person gives another a value.
Sources
- Rapid7: critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504), 30 September 2026
- watchTowr: Cisco Catalyst SD-WAN Manager vulnerability FAQ for CVE-2026-76504, 30 September 2026
- CISA: one vulnerability added to the Known Exploited Vulnerabilities catalog, 30 September 2026
