LiMP VPN
← All news

Cisco Patches SD-WAN Manager Zero-Day Granting Admin Access

Cisco Patches SD-WAN Manager Zero-Day Granting Admin Access

In short: Cisco has patched a critical vulnerability, CVE-2026-76504 (CVSS 9.8), in Catalyst SD-WAN Manager, its platform for managing enterprise network infrastructure. A URI-encoding flaw in the API let an attacker with no credentials, no MFA, and no user interaction reach a restricted API endpoint and act as an administrator. The flaw was already being exploited in the wild before public disclosure on September 30, 2026, and CISA added it to its Known Exploited Vulnerabilities catalog, ordering US federal agencies to patch by October 3.

What happened

Catalyst SD-WAN Manager is the centralized console through which administrators configure policy and segmentation across a company's entire SD-WAN fabric — a single console can manage thousands of connected devices. The bug was in how Manager handled URI encoding in HTTP requests: a specially crafted request that encoded part of the path could slip past an authentication rule meant to restrict access to one specific API endpoint.

As a result, a remote attacker could send such a request to the API of an affected system — with no credentials, no multi-factor prompt, and no user interaction — and gain access equivalent to the built-in netadmin role, which can perform any operation on the device and the SD-WAN fabric it controls.

Why this mattered

Admin-level API access is not an abstract risk: it lets an attacker map network topology, alter routing policies, weaken segmentation between network zones (say, a guest network and a corporate one), and push unauthorized configuration changes to every device connected to that Manager instance. For a company with a large branch network, that's potential control over the connectivity of dozens or hundreds of offices at once — without ever breaching an individual device directly.

Affected releases included 20.9 and earlier, plus 20.12, 20.15, 20.18, 26.1, and 26.2; Cisco's cloud-managed SD-WAN service was already patched at disclosure time. There is no workaround — the only fix is upgrading to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1.

Why this matters beyond network administrators

SD-WAN infrastructure underlies how corporate traffic — including data from remote employees and client data passing through branch offices — gets routed and segmented. Compromising the central management console for that kind of network doesn't require attacking an individual laptop or phone; it hands an attacker leverage over an entire company's network architecture at once. It's another example of how a vulnerability in enterprise gear an average user has never heard of can still affect the security of data they send over their employer's or client's network.

We've covered a similar authentication-bypass pattern before in the Citrix NetScaler gateway zero-day — the shape is the same: a flaw in a chokepoint that carries all corporate traffic gives one bug disproportionate reach.

What to do

If your organization runs Cisco Catalyst SD-WAN Manager, upgrading to a patched version isn't optional — there's no workaround, and the flaw is already being actively exploited. Until the patch is applied, Cisco recommends restricting access to the Manager's management interface to trusted hosts only and keeping it off the public internet entirely.

There's no direct action for an everyday user here, but it's a good prompt to ask your IT department or ISP whether network gear in use has been patched, especially if you work remotely over a corporate network. More breakdowns like this live on the LiMP VPN blog.

Where a VPN fits in

This flaw sits in network-provider infrastructure, not on an end-user device, so a consumer VPN doesn't close it directly. But the underlying principle holds everywhere: the more intermediate hops that can see your unencrypted traffic, the higher the risk. The LiMP VPN app encrypts the connection between your device and LiMP VPN's servers under a no-logs policy, reducing the risk of interception along the way — regardless of what hardware sits further down the route. Plans start at 69 ₽/month — details on the pricing page.

Sources