Cisco SD-WAN Manager auth bypass exploited, CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities
What Happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on Wednesday, confirming active exploitation of a critical authentication bypass in Cisco Catalyst SD-WAN Manager. The KEV listing obligates U.S. federal agencies to remediate by a binding deadline and signals to the broader private sector that the flaw is not theoretical - it is being used against real targets. Cisco has published its own advisory and patch guidance, and a dedicated Yazoul advisory tracks the issue: Cisco Catalyst SD-WAN Manager auth bypass exploited (CVE-2026-76504).
Why It Matters
SD-WAN Manager is the centralized control plane for enterprise wide-area networks. It manages device configuration, policy distribution, and fabric orchestration across potentially thousands of branch and edge devices. An authentication bypass here does not just expose one appliance - it exposes the management layer that trusts and configures the entire WAN fabric. This vulnerability arrives amid a broader wave of Cisco exploitation: Cisco ISE auth bypass (CVE-2026-76460) and Cisco Secure Email Gateway RCE (CVE-2026-76461) are both already exploited in the wild, indicating sustained adversary interest in Cisco’s identity and network management products.
Technical Details
CVE-2026-76504 is an authentication bypass affecting the SD-WAN Manager web management interface. By sending crafted requests, an unauthenticated remote attacker can bypass authentication controls and gain access to management functions. Because the flaw requires no credentials and is network-reachable, exploitation is low-complexity and suitable for automated scanning and mass exploitation.
Affected systems are Cisco Catalyst SD-WAN Manager deployments (formerly vManage) reachable from untrusted networks, whether directly internet-exposed or reachable from a compromised internal segment. Indicators of exploitation include unexpected administrative sessions, anomalous configuration pushes to edge devices, newly created management accounts, and outbound connections from the Manager to unfamiliar infrastructure.
Immediate Risk
Risk is highest for organizations with internet-facing SD-WAN Manager instances - a common but dangerous configuration. Successful exploitation can grant full administrative control over the WAN fabric, enabling traffic interception, policy manipulation, persistence via rogue accounts, and lateral movement into trusted network segments. Given confirmed exploitation and KEV inclusion, the window for unpatched systems is effectively closed. Federal agencies face a binding remediation deadline; private-sector defenders should treat this with equivalent urgency.
The CVE is formally tracked in our CVE-2026-76504 advisory with patch details and mitigation steps.
Security Insight
The cluster of exploited Cisco management-plane bugs - SD-WAN Manager, ISE, and Secure Email Gateway - mirrors the 2023-2024 pattern around edge and management appliances (Citrix Bleed, Ivanti Connect Secure, Fortinet SSL-VPN), where attackers systematically targeted the systems that enforce trust rather than the endpoints themselves. The non-obvious lesson: management interfaces are the new perimeter. Organizations that relocated workloads to cloud or zero-trust architectures often left the orchestration layer exposed on the public internet because it was considered “internal tooling.” Classify SD-WAN Manager, ISE, and similar control planes as internet-facing crown jewels, restrict management access to dedicated out-of-band networks, and enforce phishing-resistant MFA even when the vendor does not require it.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [.
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorize