Cisco SD-WAN Manager Bug Exposes Admin Access Without Login

Medium · CISA Known Exploited Vulnerabilities ·

Key points

  • CVE-2026-76504 affects Cisco's Catalyst SD-WAN Manager.
  • A remote actor with no credentials could gain admin-level access.
  • No deployment scale has been published.
  • Apply vendor fixes or stop using the product if none exist.
  • BOD 26-04 patch timelines apply to federal and regulated networks.

Cisco has disclosed a vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager. The flaw can be reached by an attacker from the network without any authentication, and successful exploitation yields administrative rights or other unauthorized entry into the system. The vendor has not shared how many installations are affected.

Any organization running the affected management platform is in scope, with internet-facing deployments facing the greatest risk. For K-12 districts and state agencies, this product often sits at the center of wide-area network control, so a compromise could ripple across school connectivity and internal services.

Administrative access to a SD-WAN management plane is serious. An intruder with that level of control could change routing policies, disable protections, or use the platform as a foothold for deeper network access. Even without confirmed exploitation, the unauthenticated nature of the bug makes rapid action important.

Cisco has published mitigations and instructions. Administrators should also assess whether their instances are reachable from the public internet. Where no mitigation or patch is available, the guidance is to stop using the product. Federal networks must patch according to BOD 26-04.

Watch for vendor updates, fixed releases, and signs of unauthorized admin activity. Review logs for unexpected configuration changes or new accounts. Until remediation is complete, limit exposure and monitor closely.

What to do now

  1. Inventory every Cisco's Catalyst SD-WAN Manager instance and flag any that are internet-accessible.
  2. Apply Cisco's mitigations immediately and follow the vendor's published instructions.
  3. Patch to a fixed release as soon as one is available, meeting BOD 26-04 deadlines.
  4. If no mitigation or patch exists, take the system offline or discontinue its use.
  5. Restrict management access to trusted internal networks and block public exposure.
  6. Review logs for unauthorized administrative actions, new accounts, or configuration changes.
  7. Document remediation and verify that exposure has been eliminated.

Original source

CISA Known Exploited Vulnerabilities

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news