NEWS

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Cisco warns attackers are actively exploiting CVE-2026-76504, a critical 9.8 CVSS auth bypass granting admin API access to SD-WAN Manager.

Dylan H.

News Desk

September 30, 2026
8 min read
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Cisco Confirms Active Exploitation of Critical SD-WAN Manager Auth Bypass

Cisco disclosed on September 30, 2026 that attackers are actively exploiting a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, the centralized console organizations use to configure and monitor their Cisco SD-WAN fabric. The flaw, tracked as CVE-2026-76504, carries a maximum-severity CVSS v3.1 score of 9.8, and lets a remote, unauthenticated attacker send a single crafted HTTP request that bypasses an authentication rule meant to restrict access to one specific API endpoint. Successful exploitation hands the attacker a working API session with the privileges of the built-in admin user — which holds the netadmin role by default — effectively granting full administrative control over the SD-WAN deployment. Cisco's Product Security Incident Response Team (PSIRT) said it became aware of the activity in September 2026 after spotting it during a technical support case, and CISA added the bug to its Known Exploited Vulnerabilities (KEV) catalog the same day under the name "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability." No workaround exists; Cisco is urging emergency patching outside normal update cycles.


Details

AttributeValue
CVE IDCVE-2026-76504
Cisco Advisorycisco-sa-sdwan-webauth-xr8beuuU
Cisco Bug IDCSCww79570
Advisory PublishedSeptember 30, 2026
CVSS v3.1 Score9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE ClassificationCWE-177 — Improper Handling of URL Encoding (Hex Encoding)
Vendor / ProductCisco Catalyst SD-WAN Manager (all configurations)
Affected Release Trains20.9 through 26.2 (releases older than 20.9 are end of support)
Authentication RequiredNone — reachable pre-authentication
Resulting PrivilegeAdmin user / netadmin role via the Manager's REST API
Discovered ByCisco PSIRT, during a Cisco TAC support case
KEV StatusAdded to CISA's KEV catalog September 30, 2026 — "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability"
Known ExploitationConfirmed active exploitation per Cisco PSIRT
WorkaroundNone available
Patched In20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1 (per train); Cisco SD-WAN Cloud already fixed in 20.15.605

How It Worked

A One-Character Encoding Trick Against the Login Filter

CVE-2026-76504 lives in how Catalyst SD-WAN Manager handles URI encoding during API session authentication. The Manager's web front end restricts direct access to its j_security_check login-processing endpoint so it can only be reached through the intended authentication flow. According to Cisco and corroborating analysis from Rapid7, the restriction is enforced by matching the literal request path — and that match breaks if even a single character in the path is percent-encoded. By sending a request such as POST /%6a_security_check (where %6a is the hex-encoded form of the letter "j") instead of the plain-text path, an attacker's request slips past the access rule meant to gate that endpoint while the underlying application logic still treats it as a valid authentication request.

From Encoding Trick to Admin API Session

Because the bypass targets the authentication-handling endpoint itself, a successful request returns a working, authenticated API session — without the attacker ever supplying valid credentials. Cisco's advisory notes that session carries the rights of the Manager's built-in admin account, which runs under the netadmin role by default. That role is the highest privilege tier in Catalyst SD-WAN Manager, giving an attacker the ability to read and modify device configuration, provision or de-provision network elements, and perform essentially any operation exposed through the Manager's REST API — equivalent to full administrative takeover of the SD-WAN control plane.

Discovery and Confirmed In-the-Wild Use

Cisco PSIRT said it identified the exploitation activity during the handling of a customer Technical Assistance Center (TAC) case in September 2026, rather than through a researcher disclosure. That detection path — spotting live exploitation first, patch second — is consistent with the emergency nature of the advisory: Cisco shipped fixed releases across all six active trains the same day it published the advisory, and CISA added the flaw to its KEV catalog within hours, giving U.S. federal civilian agencies a mandated remediation deadline under Binding Operational Directive 22-01.

Indicators of Compromise

Cisco's advisory and Rapid7's technical write-up point defenders to two log sources for signs of attempted or successful exploitation:

  • /var/log/nms/containers/service-proxy/serviceproxy-access.log — look for requests against the j_security_check path containing percent-encoded characters, originating from unrecognized source IP addresses.
  • /var/log/nms/vmanage-server.log — look for authenticated activity tied to reserved system accounts, specifically usernames beginning with viptela-reserved-, which should not normally appear in interactive session logs.

Impact Assessment

Impact AreaDescription
ConfidentialityAdmin-level API access exposes the full SD-WAN fabric's device configuration, routing policy, and credential material managed through the Manager
IntegrityAn attacker holding the netadmin role can modify routing, security policy, and device provisioning across every site attached to the SD-WAN deployment
AvailabilityMalicious configuration changes pushed through the API can disrupt WAN connectivity across an organization's entire branch and data-center footprint
ScopeAny Cisco Catalyst SD-WAN Manager instance on an affected release train — Cisco states the flaw applies "regardless of system configuration"
Internet ExposureDeployments with SD-WAN Manager's management interface reachable from the internet face the highest immediate risk, since the exploit requires no credentials
Compounding TrendThe Hacker News reports eight separate Cisco SD-WAN vulnerabilities have been added to CISA's KEV catalog during 2026, signaling sustained, repeated attacker interest in SD-WAN control-plane infrastructure

Recommendations

For Network and SD-WAN Administrators

  1. Patch immediately and outside normal change windows — upgrade to the first fixed release for your train: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. There is no workaround, so patching is the only mitigation Cisco offers.
  2. Confirm Cisco SD-WAN Cloud (cloud-managed) customers are current — Cisco states that offering was already remediated in release 20.15.605 and requires no customer action, but verify your tenant's version regardless.
  3. Remove SD-WAN Manager's management interface from direct internet exposure. Restrict access to trusted management networks or a VPN, and place the interface behind a firewall that limits inbound access to known administrative hosts.
  4. Retire any release train older than 20.9 — those builds are end of support and were not evaluated for a fix; migrate to a supported, patched train.

For Security Operations Teams

  1. Hunt immediately for percent-encoded j_security_check requests in serviceproxy-access.log and for viptela-reserved- account activity in vmanage-server.log, going back to early September 2026 given the confirmed active-exploitation timeline.
  2. Treat any internet-facing, unpatched SD-WAN Manager as potentially compromised rather than merely vulnerable, given Cisco's confirmation of in-the-wild attacks preceding the patch release.
  3. Prioritize this CVE in vulnerability management workflows per its CISA KEV listing — federal agencies face a mandated remediation deadline, and the same urgency applies to any organization running internet-reachable Cisco SD-WAN infrastructure.
  4. Rotate administrative credentials and API tokens associated with any SD-WAN Manager instance where exploitation indicators are found, since a compromised admin session could have been used to create new credentials or persistence mechanisms.

For Broader IT Teams

  1. Inventory every Cisco Catalyst SD-WAN Manager deployment across the organization, including instances managed by third-party MSPs, and confirm patch status for each.
  2. Document SD-WAN Manager as critical control-plane infrastructure in asset and risk registers — compromise here affects the WAN connectivity of every dependent site, not just a single device.
  3. Stay alert for Cisco's pattern of repeated SD-WAN disclosures in 2026 and build a recurring review cadence for Cisco security advisories rather than treating each one as an isolated event.

Key Takeaways

  1. CVE-2026-76504 is a critical (CVSS 9.8) authentication bypass in Cisco Catalyst SD-WAN Manager that lets an unauthenticated remote attacker gain an admin-level API session using a single percent-encoded character in the j_security_check request path.
  2. Active exploitation is confirmed — Cisco PSIRT discovered the activity via a TAC support case in September 2026, and the flaw was added to CISA's KEV catalog on the same day as the advisory, September 30, 2026.
  3. No workaround exists. Fixed releases are available for every affected train (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1), and Cisco SD-WAN Cloud customers were already patched in 20.15.605.
  4. Successful exploitation grants netadmin-level control over the SD-WAN fabric's API, enabling configuration changes, data exposure, and potential WAN-wide disruption.
  5. Defenders should hunt now, checking serviceproxy-access.log for encoded j_security_check requests and vmanage-server.log for anomalous viptela-reserved- account activity, rather than waiting for patch deployment to complete.
  6. This marks the eighth Cisco SD-WAN vulnerability added to CISA's KEV catalog in 2026, underscoring that SD-WAN control-plane software remains a persistent, high-value target for attackers.

Sources