Cisco SD-WAN Manager Has a 9.8 Critical Flaw Under Active Attack: Patch Now
A critical authentication bypass in Cisco Catalyst SD-WAN Manager is giving attackers admin-level access to business networks without a username or password. It's being actively exploited right now, and there is no workaround.
According to The Hacker News, the flaw (CVSS 9.8) stems from improper URI encoding in the Cisco Catalyst SD-WAN Manager API. An attacker sends a single crafted HTTP request and walks straight in as an admin user. No credentials required. Cisco confirmed active exploitation began in September 2026, and this is now the eighth Cisco SD-WAN CVE added to CISA's Known Exploited Vulnerabilities list in 2026 alone, which tells you how heavily targeted this platform is.
Cisco's SD-WAN platform is used by businesses managing branch offices, remote sites, and distributed connectivity, which is common across Sydney, Central West NSW, Brisbane, and Melbourne. If that's your setup, an attacker with admin access to your SD-WAN Manager can reroute traffic, intercept communications, or use your network as a launchpad for deeper attacks. Upgrading to a fixed release is the only fix Cisco has issued. Check your service-proxy access logs for unknown IPs hitting /j_security_check, and watch for any usernames starting with "viptela-reserved-" as indicators of compromise. Your managed IT provider should be auditing and patching this today.
Written by Dan Briggs, Senior IT Consultant, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across hospitality, not-for-profit, and financial services sectors Australia-wide.
Frequently Asked Questions
Unsure If Your Cisco Gear Is Patched?
All IT's network security team can audit your Cisco environment and apply patches before attackers find their way in.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
