Cisco Confirms Active Exploitation of Critical SD-WAN Manager Auth Bypass
Cisco disclosed on September 30, 2026 that attackers are actively exploiting a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, the centralized console organizations use to configure and monitor their Cisco SD-WAN fabric. The flaw, tracked as CVE-2026-76504, carries a maximum-severity CVSS v3.1 score of 9.8, and lets a remote, unauthenticated attacker send a single crafted HTTP request that bypasses an authentication rule meant to restrict access to one specific API endpoint. Successful exploitation hands the attacker a working API session with the privileges of the built-in admin user — which holds the netadmin role by default — effectively granting full administrative control over the SD-WAN deployment. Cisco's Product Security Incident Response Team (PSIRT) said it became aware of the activity in September 2026 after spotting it during a technical support case, and CISA added the bug to its Known Exploited Vulnerabilities (KEV) catalog the same day under the name "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability." No workaround exists; Cisco is urging emergency patching outside normal update cycles.
Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-76504 |
| Cisco Advisory | cisco-sa-sdwan-webauth-xr8beuuU |
| Cisco Bug ID | CSCww79570 |
| Advisory Published | September 30, 2026 |
| CVSS v3.1 Score | 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE Classification | CWE-177 — Improper Handling of URL Encoding (Hex Encoding) |
| Vendor / Product | Cisco Catalyst SD-WAN Manager (all configurations) |
| Affected Release Trains | 20.9 through 26.2 (releases older than 20.9 are end of support) |
| Authentication Required | None — reachable pre-authentication |
| Resulting Privilege | Admin user / netadmin role via the Manager's REST API |
| Discovered By | Cisco PSIRT, during a Cisco TAC support case |
| KEV Status | Added to CISA's KEV catalog September 30, 2026 — "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability" |
| Known Exploitation | Confirmed active exploitation per Cisco PSIRT |
| Workaround | None available |
| Patched In | 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1 (per train); Cisco SD-WAN Cloud already fixed in 20.15.605 |
How It Worked
A One-Character Encoding Trick Against the Login Filter
CVE-2026-76504 lives in how Catalyst SD-WAN Manager handles URI encoding during API session authentication. The Manager's web front end restricts direct access to its j_security_check login-processing endpoint so it can only be reached through the intended authentication flow. According to Cisco and corroborating analysis from Rapid7, the restriction is enforced by matching the literal request path — and that match breaks if even a single character in the path is percent-encoded. By sending a request such as POST /%6a_security_check (where %6a is the hex-encoded form of the letter "j") instead of the plain-text path, an attacker's request slips past the access rule meant to gate that endpoint while the underlying application logic still treats it as a valid authentication request.
From Encoding Trick to Admin API Session
Because the bypass targets the authentication-handling endpoint itself, a successful request returns a working, authenticated API session — without the attacker ever supplying valid credentials. Cisco's advisory notes that session carries the rights of the Manager's built-in admin account, which runs under the netadmin role by default. That role is the highest privilege tier in Catalyst SD-WAN Manager, giving an attacker the ability to read and modify device configuration, provision or de-provision network elements, and perform essentially any operation exposed through the Manager's REST API — equivalent to full administrative takeover of the SD-WAN control plane.
Discovery and Confirmed In-the-Wild Use
Cisco PSIRT said it identified the exploitation activity during the handling of a customer Technical Assistance Center (TAC) case in September 2026, rather than through a researcher disclosure. That detection path — spotting live exploitation first, patch second — is consistent with the emergency nature of the advisory: Cisco shipped fixed releases across all six active trains the same day it published the advisory, and CISA added the flaw to its KEV catalog within hours, giving U.S. federal civilian agencies a mandated remediation deadline under Binding Operational Directive 22-01.
Indicators of Compromise
Cisco's advisory and Rapid7's technical write-up point defenders to two log sources for signs of attempted or successful exploitation:
/var/log/nms/containers/service-proxy/serviceproxy-access.log— look for requests against thej_security_checkpath containing percent-encoded characters, originating from unrecognized source IP addresses./var/log/nms/vmanage-server.log— look for authenticated activity tied to reserved system accounts, specifically usernames beginning withviptela-reserved-, which should not normally appear in interactive session logs.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Admin-level API access exposes the full SD-WAN fabric's device configuration, routing policy, and credential material managed through the Manager |
| Integrity | An attacker holding the netadmin role can modify routing, security policy, and device provisioning across every site attached to the SD-WAN deployment |
| Availability | Malicious configuration changes pushed through the API can disrupt WAN connectivity across an organization's entire branch and data-center footprint |
| Scope | Any Cisco Catalyst SD-WAN Manager instance on an affected release train — Cisco states the flaw applies "regardless of system configuration" |
| Internet Exposure | Deployments with SD-WAN Manager's management interface reachable from the internet face the highest immediate risk, since the exploit requires no credentials |
| Compounding Trend | The Hacker News reports eight separate Cisco SD-WAN vulnerabilities have been added to CISA's KEV catalog during 2026, signaling sustained, repeated attacker interest in SD-WAN control-plane infrastructure |
Recommendations
For Network and SD-WAN Administrators
- Patch immediately and outside normal change windows — upgrade to the first fixed release for your train:
20.9.10.1,20.12.8.2,20.15.6.1,20.18.4.1,26.1.2.1, or26.2.1. There is no workaround, so patching is the only mitigation Cisco offers. - Confirm Cisco SD-WAN Cloud (cloud-managed) customers are current — Cisco states that offering was already remediated in release
20.15.605and requires no customer action, but verify your tenant's version regardless. - Remove SD-WAN Manager's management interface from direct internet exposure. Restrict access to trusted management networks or a VPN, and place the interface behind a firewall that limits inbound access to known administrative hosts.
- Retire any release train older than 20.9 — those builds are end of support and were not evaluated for a fix; migrate to a supported, patched train.
For Security Operations Teams
- Hunt immediately for percent-encoded
j_security_checkrequests inserviceproxy-access.logand forviptela-reserved-account activity invmanage-server.log, going back to early September 2026 given the confirmed active-exploitation timeline. - Treat any internet-facing, unpatched SD-WAN Manager as potentially compromised rather than merely vulnerable, given Cisco's confirmation of in-the-wild attacks preceding the patch release.
- Prioritize this CVE in vulnerability management workflows per its CISA KEV listing — federal agencies face a mandated remediation deadline, and the same urgency applies to any organization running internet-reachable Cisco SD-WAN infrastructure.
- Rotate administrative credentials and API tokens associated with any SD-WAN Manager instance where exploitation indicators are found, since a compromised admin session could have been used to create new credentials or persistence mechanisms.
For Broader IT Teams
- Inventory every Cisco Catalyst SD-WAN Manager deployment across the organization, including instances managed by third-party MSPs, and confirm patch status for each.
- Document SD-WAN Manager as critical control-plane infrastructure in asset and risk registers — compromise here affects the WAN connectivity of every dependent site, not just a single device.
- Stay alert for Cisco's pattern of repeated SD-WAN disclosures in 2026 and build a recurring review cadence for Cisco security advisories rather than treating each one as an isolated event.
Key Takeaways
- CVE-2026-76504 is a critical (CVSS 9.8) authentication bypass in Cisco Catalyst SD-WAN Manager that lets an unauthenticated remote attacker gain an admin-level API session using a single percent-encoded character in the
j_security_checkrequest path. - Active exploitation is confirmed — Cisco PSIRT discovered the activity via a TAC support case in September 2026, and the flaw was added to CISA's KEV catalog on the same day as the advisory, September 30, 2026.
- No workaround exists. Fixed releases are available for every affected train (
20.9.10.1,20.12.8.2,20.15.6.1,20.18.4.1,26.1.2.1,26.2.1), and Cisco SD-WAN Cloud customers were already patched in20.15.605. - Successful exploitation grants netadmin-level control over the SD-WAN fabric's API, enabling configuration changes, data exposure, and potential WAN-wide disruption.
- Defenders should hunt now, checking
serviceproxy-access.logfor encodedj_security_checkrequests andvmanage-server.logfor anomalousviptela-reserved-account activity, rather than waiting for patch deployment to complete. - This marks the eighth Cisco SD-WAN vulnerability added to CISA's KEV catalog in 2026, underscoring that SD-WAN control-plane software remains a persistent, high-value target for attackers.