Local Melbourne technicians available

Careers•Remote support•Contact
All newsroom

Newsroom · Cyber Security

Cisco SD-WAN Manager: Critical Authentication Bypass Flaw

Australian healthcare organisations and Melbourne businesses using Cisco SD-WAN Manager should review their systems for signs of compromise and upgrade to a fixed release.

Cisco has warned that attackers are actively exploiting a critical authentication bypass flaw in its SD-WAN Manager software, which could allow unauthenticated access to the system's API. The flaw, tracked as CVE-2026-76504, has a CVSS score of 9.8 and affects SD-WAN Manager regardless of system configuration.

Vulnerability Details

The flaw, tracked as CVE-2026-76504, has a CVSS score of 9.8 and affects SD-WAN Manager regardless of system configuration. It allows an unauthenticated attacker to reach the Manager's API as the admin user by sending a specially crafted HTTP request. The cause is improper handling of uniform resource identifier (URI) encoding, and the flaw allows a request to slip past an authentication rule meant to protect a specific API endpoint.

Impact and Mitigation

Cisco's Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability in September. The flaw was found while resolving a support case. There is no workaround for this flaw, and Cisco strongly recommends upgrading to a fixed release. The first fixed releases for each release train are: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Customers running anything earlier than 20.9 must migrate to a fixed release.

Checking for Signs of Compromise

To determine whether a Manager has been compromised, customers can check the serviceproxy-access.log and vmanage-server.log files for j_security_check entries from unknown or unauthorized IP addresses. They can also open a Severity 3 case with Cisco's Technical Assistance Centre (TAC) and include CVE-2026-76504 in the title. The U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalogue has listed eight Cisco SD-WAN flaws added in 2026, including this one.

Practical Response

Australian healthcare organisations and Melbourne businesses using Cisco SD-WAN Manager should review their systems for signs of compromise and upgrade to a fixed release. They should also restrict access to the Manager from unsecured networks such as the internet, and only allow known, trusted hosts to access the system. The IT support team should verify that the upgrade has been successfully applied and that the system is no longer vulnerable to the flaw. If a compromise is suspected, the team should escalate the issue to the security lead for further investigation and remediation.

Talk to Podium IT

Need a clear next step?

Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.

Encrypted in transit Securely stored

This form uses server-side validation, bot protection and rate limiting. For urgent support, call us directly.

General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.