Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Cisco SD-WAN Manager Has a 9.8 Critical Flaw Under Active Attack: Patch Now

Cisco SD-WAN Manager Has a 9.8 Critical Flaw Under Active Attack: Patch Now

A critical authentication bypass in Cisco Catalyst SD-WAN Manager is giving attackers admin-level access to business networks without a username or password. It's being actively exploited right now, and there is no workaround.

Act Immediately: CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on 30 September 2026. US federal agencies have until 3 October to patch. Australian businesses should treat the same deadline as their own.

According to The Hacker News, the flaw (CVSS 9.8) stems from improper URI encoding in the Cisco Catalyst SD-WAN Manager API. An attacker sends a single crafted HTTP request and walks straight in as an admin user. No credentials required. Cisco confirmed active exploitation began in September 2026, and this is now the eighth Cisco SD-WAN CVE added to CISA's Known Exploited Vulnerabilities list in 2026 alone, which tells you how heavily targeted this platform is.

Cisco's SD-WAN platform is used by businesses managing branch offices, remote sites, and distributed connectivity, which is common across Sydney, Central West NSW, Brisbane, and Melbourne. If that's your setup, an attacker with admin access to your SD-WAN Manager can reroute traffic, intercept communications, or use your network as a launchpad for deeper attacks. Upgrading to a fixed release is the only fix Cisco has issued. Check your service-proxy access logs for unknown IPs hitting /j_security_check, and watch for any usernames starting with "viptela-reserved-" as indicators of compromise. Your managed IT provider should be auditing and patching this today.

Written by Dan Briggs, Senior IT Consultant, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across hospitality, not-for-profit, and financial services sectors Australia-wide.


Frequently Asked Questions

CVE-2026-76504 is a critical (CVSS 9.8) authentication bypass in Cisco Catalyst SD-WAN Manager. An unauthenticated remote attacker can send a crafted HTTP request to the API and gain admin-level access to the system without any credentials.
If your organisation runs Cisco Catalyst SD-WAN Manager and hasn't applied Cisco's latest patch, treat it as at risk. Contact your IT provider straight away to confirm whether your environment is exposed.
No. Cisco has not published a workaround for this vulnerability. Upgrading to a fixed release is the only resolution.
Cisco advises checking service-proxy access logs for unknown IPs hitting /j_security_check, and watching for usernames beginning with "viptela-reserved-". All IT can review your network logs and access history for signs of suspicious activity.

Unsure If Your Cisco Gear Is Patched?

All IT's network security team can audit your Cisco environment and apply patches before attackers find their way in.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →