Cisco is urging customers to patch Cisco Catalyst SD-WAN Manager immediately after disclosing a critical authentication-bypass flaw that its security team says is already being exploited in the wild.

The vulnerability, tracked as CVE-2026-76504, carries a CVSS score of 9.8 out of 10. It sits in the login logic: a request for "j_security_check" is mishandled as "%6a_security_check" because of incorrect URL decoding, a bug in the input validation of URL processing. The practical effect is that a remote attacker can reach a vulnerable system without authenticating and obtain administrator privileges, then use the integrated API to control the appliance remotely.

Cisco's advisory names two ways to hunt for signs of exploitation. Administrators should inspect /var/log/nms/serviceproxy-access.log and /var/log/nms/vmanage-server.log for the string "/%6a_security_check". Cisco cautions that the string can also appear in legitimate traffic, so a hit is a prompt for closer analysis rather than proof of compromise.

Because Cisco maintains half a dozen supported branches of SD-WAN Manager, there are as many fixed builds. Deployments older than 20.9 should move to at least 20.9; branch 20.9 should go to 20.9.10.1; 20.12 to 20.12.8.2; 20.15 to 20.15.6.1; 20.18 to 20.18.4.1; 26.1 to 26.1.2.1; and 26.2 to 26.2.1. Cisco SD-WAN Cloud customers are directed to version 20.15.605. Updates are available through the usual download portal.

The Product Security Incident Response Team says it is aware of active attacks dating back to an unspecified point in September 2026. Organizations that suspect an appliance has already been compromised should open a case with Cisco's Technical Assistance Center rather than simply patching and moving on.

The disclosure continues a bruising run for the product. Critical vulnerabilities in SD-WAN Manager were exploited in April, May, June, August and now September 2026, and eight flaws in the platform have landed on the US cybersecurity agency CISA's list of known exploited vulnerabilities this year alone. That pattern — repeated, actively exploited, remotely reachable bugs in a widely deployed branch-office and WAN management plane — is why administrators are being told not to defer the update.