
CISA Adds CVE-2026-76504 Cisco SD-WAN Auth Bypass to KEV After September Exploitation
CISA's addition of CVE-2026-76504 highlights sustained targeting of Cisco SD-WAN Manager with eight related KEV entries in 2026. The vulnerability enables unauthenticated admin API access via crafted HTTP requests. Evidence trails and deployment patterns indicate attackers will continue prioritizing this surface.
The flaw stems from improper URI encoding handling in HTTP requests to the /j_security_check endpoint, allowing unauthenticated remote attackers to reach admin-level API access. Cisco released IoCs focused on audit logs in /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for anomalous POSTs tied to viptela-reserved- accounts. Federal agencies must patch by October 3, 2026.
Eight SD-WAN CVEs reached KEV in 2026 alone, confirming the platform's value as a single management pane for large networks. Procurement records and job postings from major integrators show continued heavy SD-WAN deployments in critical infrastructure despite repeated bypass patterns. This concentration creates persistent high-value targets that attackers repeatedly prioritize over isolated devices.
Original coverage omitted the accelerating role of AI-assisted reconnaissance and payload generation in locating and weaponizing such encoding flaws faster than manual review cycles. Contract awards for automated threat hunting have not kept pace with observed exploitation velocity. Next indicators will appear in public log samples or additional KEV entries within 60 days.
CISA: At least three additional SD-WAN CVEs added to KEV before December 31 2026
Sources (3)
- [1]CISA Known Exploited Vulnerabilities Catalog(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [2]Cisco Security Advisory(https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-auth-bypass)
- [3]watchTowr Threat Intelligence Statement(https://watchtowr.com/blog/cisco-sdwan-kev-2026)