Critical Vulnerability

Cisco SD-WAN Manager auth bypass exploited, CISA KEV

By Yazoul AI · automated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities

What Happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on Wednesday, confirming active exploitation of a critical authentication bypass in Cisco Catalyst SD-WAN Manager. The KEV listing obligates U.S. federal agencies to remediate by a binding deadline and signals to the broader private sector that the flaw is not theoretical - it is being used against real targets. Cisco has published its own advisory and patch guidance, and a dedicated Yazoul advisory tracks the issue: Cisco Catalyst SD-WAN Manager auth bypass exploited (CVE-2026-76504).

Why It Matters

SD-WAN Manager is the centralized control plane for enterprise wide-area networks. It manages device configuration, policy distribution, and fabric orchestration across potentially thousands of branch and edge devices. An authentication bypass here does not just expose one appliance - it exposes the management layer that trusts and configures the entire WAN fabric. This vulnerability arrives amid a broader wave of Cisco exploitation: Cisco ISE auth bypass (CVE-2026-76460) and Cisco Secure Email Gateway RCE (CVE-2026-76461) are both already exploited in the wild, indicating sustained adversary interest in Cisco’s identity and network management products.

Technical Details

CVE-2026-76504 is an authentication bypass affecting the SD-WAN Manager web management interface. By sending crafted requests, an unauthenticated remote attacker can bypass authentication controls and gain access to management functions. Because the flaw requires no credentials and is network-reachable, exploitation is low-complexity and suitable for automated scanning and mass exploitation.

Affected systems are Cisco Catalyst SD-WAN Manager deployments (formerly vManage) reachable from untrusted networks, whether directly internet-exposed or reachable from a compromised internal segment. Indicators of exploitation include unexpected administrative sessions, anomalous configuration pushes to edge devices, newly created management accounts, and outbound connections from the Manager to unfamiliar infrastructure.

Immediate Risk

Risk is highest for organizations with internet-facing SD-WAN Manager instances - a common but dangerous configuration. Successful exploitation can grant full administrative control over the WAN fabric, enabling traffic interception, policy manipulation, persistence via rogue accounts, and lateral movement into trusted network segments. Given confirmed exploitation and KEV inclusion, the window for unpatched systems is effectively closed. Federal agencies face a binding remediation deadline; private-sector defenders should treat this with equivalent urgency.

The CVE is formally tracked in our CVE-2026-76504 advisory with patch details and mitigation steps.

Security Insight

The cluster of exploited Cisco management-plane bugs - SD-WAN Manager, ISE, and Secure Email Gateway - mirrors the 2023-2024 pattern around edge and management appliances (Citrix Bleed, Ivanti Connect Secure, Fortinet SSL-VPN), where attackers systematically targeted the systems that enforce trust rather than the endpoints themselves. The non-obvious lesson: management interfaces are the new perimeter. Organizations that relocated workloads to cloud or zero-trust architectures often left the orchestration layer exposed on the public internet because it was considered “internal tooling.” Classify SD-WAN Manager, ISE, and similar control planes as internet-facing crown jewels, restrict management access to dedicated out-of-band networks, and enforce phishing-resistant MFA even when the vendor does not require it.

Further Reading

Share:

Never miss a security update

Get real-time security alerts delivered to your preferred platform.

Related News

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.