CODERED VTA

Cisco Catalyst SD WAN Manager Follow Up Adds Two More Confirmed Exploited Bypass Flaws

High
Network racks and cabling
Photo by Jefferson Lab on Flickr

VTA-2026-000421, published on 1 October 2026, covered the critical API authentication bypass in Cisco Catalyst SD-WAN Manager tracked as CVE-2026-76504, which the vendor disclosed on 30 September 2026 and which CISA added to its Known Exploited Vulnerabilities catalog the same day. The incident has since widened in scope, and this update exists to record that change rather than to repeat the original account. Two further authentication bypasses in the same Catalyst SD-WAN control plane are now in scope for the same remediation and hunting effort: CVE-2026-20127 and CVE-2026-20182, both disclosed earlier in 2026 and both confirmed exploited in the wild. CVE-2026-20127 was added to CISA KEV on 25 February 2026 and carries a FIRST EPSS probability of 88.5% of exploitation in the next 30 days; CVE-2026-20182 was added on 14 May 2026 and carries an EPSS probability of 91.5%. Any organisation running an on-premises Catalyst SD-WAN Manager instance, particularly one with management ports reachable from the internet, falls within scope of all three issues.

CVE-2026-76504 remains the newest of the three and the one with the clearest published mechanism. It is an improper handling of URL encoding weakness, classified as CWE-177, in which a crafted HTTP request defeats the authentication rule applied to one specific API endpoint. An unauthenticated remote attacker who reaches that endpoint gains API access with the privileges of the admin user, which is why the flaw scores CVSSv3.1 9.8 with network attack vector, low complexity, no privileges and no user interaction. The weakness is present regardless of how the system is configured, and the vendor has published no workaround, only fixed software and a network-restriction mitigation. The two newly added CVEs are separate problems: both are unauthenticated peering authentication flaws in the vdaemon service and adjacent parts of its networking stack, distinct from one another and distinct from the API path abused by CVE-2026-76504. Beyond that characterisation, no exploitation mechanics for the vdaemon issues appear in the material reviewed, so no chain should be assumed for them.

The significance of this update is the pattern rather than any single bug. Three separate unauthenticated authentication bypasses in the same internet-facing SD-WAN control component have now been confirmed exploited inside a single calendar year, each one landing in CISA KEV, and the two older entries carry EPSS probabilities near and above 90% that exploitation continues. Catalyst SD-WAN Manager is not an edge appliance but the orchestration brain of the WAN fabric, so admin-level API access translates into visibility of device inventory, control over templates and policy pushed to branch routers, and a credible route to influence traffic across every site the fabric serves. Organisations that remediated only CVE-2026-76504 after the first advisory may still be carrying exposure to the two vdaemon flaws if those systems were never brought to a fixed release, and the recurrence of this bug class suggests the attack surface is under sustained attention. Fixed software exists for all affected trains, and the Cisco-managed cloud service was remediated in release 20.15.605 with no customer action needed, but on-premises operators who have not reached a fixed release remain exposed to flaws that are being used against real targets today. Because the compromise path leaves an attacker operating as a legitimate admin, post-exploitation activity may be indistinguishable from routine administration in logs that only record successful authenticated API calls.

Attack Surface

Infrastructure, System Management Service, Web Application

Tactics

Initial Access, Defense Evasion, Privilege Escalation

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1133 – External Remote Services
  • T1078 – Valid Accounts

SuperPRO's Threat Countermeasures Procedures

  1. Confirm every on-premises Catalyst SD-WAN Manager is on a release that fixes CVE-2026-76504: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1. Anything earlier than 20.9 has no fix in train and must be migrated to one of the listed releases.
  2. Re-check the same estate against the two newly in-scope KEV entries, CVE-2026-20127 and CVE-2026-20182 in the vdaemon peering authentication path, and validate the running version against the Cisco advisory for each rather than assuming the CVE-2026-76504 upgrade also covered them.
  3. Where an upgrade window cannot be met, apply the vendor's interim mitigation by placing Catalyst SD-WAN control components behind a filtering device and allowing management and API access only from a named list of trusted administrative hosts; this is a stopgap only, as no workaround exists for CVE-2026-76504 itself.
  4. Generate an admin-tech bundle on each internet-reachable manager using the request admin-tech command and review it for compromise; Cisco accepts a Severity 3 TAC case with CVE-2026-76504 in the title for assisted analysis of that bundle.
  5. Hunt API access logs on the manager for unauthenticated or unexpected requests to management endpoints containing percent-encoded or double-encoded path segments, since CVE-2026-76504 is a URL-encoding handling flaw (CWE-177) exercised through a crafted HTTP request.
  6. Audit the manager for post-exploitation signs of admin abuse: newly created or modified local accounts, unexpected device template and policy changes pushed to branch routers, and API-initiated configuration commits outside change windows.
  7. Verify Cisco SD-WAN Cloud (Cisco Managed) tenants are running release 20.15.605 or later, which already carries the fix and requires no customer action, and record that confirmation so cloud-hosted instances are not re-scanned as exposed.

Source

Code Red Cyber / VTA – coderedcyber.ai