Skip to content

Build1 publisher2 min readPublished

Attackers use a URI-encoding bug to run Cisco SD-WAN Manager's API as admin

Cisco says attackers are exploiting CVE-2026-76504, a 9.8 CVSS flaw that lets anyone reaching SD-WAN Manager's API act as admin with no credentials. Managers patched for the May and June flaws still need the new releases, because those fixes predate this one.

The Engineer · Build desk

Illustration accompanying Attackers use a URI-encoding bug to run Cisco SD-WAN Manager's API as admin

What happened

  • The flaw is in how the Manager's login-session API handles URI encoding: a request that encodes part of its path slips past a rule meant to guard a single endpoint.
  • By default the admin user holds the netadmin role, which Cisco describes as allowed to perform all operations on the device.
  • Cisco's PSIRT learned of the exploitation in September, after the flaw surfaced during a TAC support case.
  • Cisco-managed SD-WAN Cloud is already fixed in release 20.15.605, and Cloud Hosted environments already have the network access mitigation in place.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Blocking the internet narrows exposure without closing it: a compromised host already on a network that can reach the Manager API meets the exploit's only precondition.
  • decision Operators on 20.10, 20.11, 20.13, 20.14 or 20.16, or on Cloud-Pro or FedRAMP deployments, cannot find their fix in the table and must either move to a listed train or get a direct answer from Cisco.
  • cost Upgrading closes the entry point, but Cisco has not said it evicts an attacker already inside, so teams whose Manager was reachable from untrusted networks also carry the cost of reviewing its admin activity.

The fault is in how the Manager parses HTTP requests, in code no operator configures [3]. That matches two other details in the advisory. The flaw affects SD-WAN Manager regardless of configuration [7]. There is no workaround [10].

The exploit needs network reachability to the Manager API and nothing more. The attacker needs no account or stolen session, and no user has to interact [4]. According to Cisco, any Manager exposed to the internet is at risk of compromise [21]. The admin account matters because the Manager pushes configuration and policy to every edge router in the fabric [6]. The dev.to write-up concludes, correctly in my view, that admin API access on the controller is effectively administrative reach across the WAN it manages [18].

CVE-2026-76504 is separate from CVE-2026-20182, fixed in May, and from CVE-2026-20245 and CVE-2026-20262, fixed in June [19]. The fixed releases for all three are older than the ones listed for this bug, so a Manager sitting at the June fix level is still below the new floor on its train [19]. This is the fourth SD-WAN Manager flaw Cisco has patched since May [8]. Six release trains get a first fixed release [2]. Anything earlier than 20.9 has to migrate to a fixed release [22].

Cisco's interim mitigation will be familiar to anyone who has read its SD-WAN hardening guide [1]. For on-prem Managers that cannot be upgraded immediately, Cisco advises restricting access from unsecured networks such as the internet [11]. Where internet access is required, Cisco says only known, trusted hosts should be allowed in, with control components behind a firewall [11]. The hardening guide already says ports 443, 22 and 830 should not be exposed directly to the internet, and that HTTPS access to the Manager should come from a jump host or a similar management source [16]. A Manager built to that guide already meets the interim advice [1]. Cisco says the mitigation worked in a test environment, and it advises customers to assess the impact on their own networks before relying on it [20].

Cisco confirmed the exploitation on September 30 [1]. The advisory does not say how many customers were hit, when attacks began, who is behind them, or what attackers did once inside [15].

What to watch

  • Whether Cisco revises the advisory to list fixed releases for the 20.10, 20.11, 20.13, 20.14 and 20.16 trains, or to state the status of Cloud-Pro and FedRAMP deployments.
  • Whether Cisco says if upgrading removes an attacker who already holds admin access, or publishes indicators of compromise for the Manager.
  • Any disclosure of how many customers were hit and when exploitation began.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories