Cisco published an advisory on September 30 for CVE-2026-76504, a critical (CVSS 9.8) authentication bypass in the API of Catalyst SD-WAN Manager (formerly vManage). An unauthenticated remote attacker can reach the Manager’s API as the admin user. Cisco PSIRT says the flaw is being exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog the same day. Cisco lists no workaround, so the fix is to upgrade.
What happened
The bug is in API session-based authentication handling, classified as improper handling of URL encoding (CWE-177). Per public analysis, an attacker sends a crafted HTTP request in which a single character of the j_security_check path is URL-encoded. The encoded path slips past the authentication rule that should gate the request, and the request is processed with admin privileges on the API.
No credentials, prior foothold or user interaction are needed. Cisco states the flaw affects the product regardless of configuration. Cisco PSIRT became aware of exploitation activity in September 2026. At the time of writing the vendor has not attributed it to a named actor, and public reporting does not tie it to earlier SD-WAN campaigns.
Technical details
This is a path-normalization mismatch, the same pattern behind many proxy and servlet-filter bypasses. The component that enforces “this path requires authentication” matches on the raw path, while the component that routes the request decodes it first. One percent-encoded character is enough for the two to disagree. The request is then treated as pre-authenticated and served by the admin API.
Admin API access on SD-WAN Manager is effectively control of the overlay. It allows:
- Reading and altering device templates and policies pushed to edge routers.
- Creating or modifying users and API keys for persistence.
- Pulling configuration, certificates and inventory for the whole fabric.
Earlier Cisco SD-WAN zero-days this year were used in exactly these ways. Some were followed by configuration changes pushed to edge devices. We have not seen confirmation that this exploitation did the same, but the capability exists.
Who’s affected
All Catalyst SD-WAN Manager deployments running vulnerable releases are affected, in any configuration. Exposure is greatest for Managers whose web or API ports are reachable from the internet. The Cisco-managed SD-WAN cloud service was already patched (release 20.15.605), so those customers need to do nothing.
Fixed releases
Cisco lists fixes across several trains, including:
- 20.9.10.1
- 20.12.8.2
- 20.15.6.1
- 20.18.4.1
- 26.1.2.1
- 26.2.1
Confirm your exact train against the advisory before upgrading. Releases outside the supported trains need a migration to a fixed one.
Mitigation and response
- Patch now. With active exploitation and a KEV listing, treat this as emergency change. CISA’s federal remediation deadline follows the KEV entry.
- Take the Manager off the internet. Restrict management and API access to a dedicated management network or VPN. Cisco offers no workaround, but removing exposure cuts the attack surface.
- Hunt before and after patching. Patching does not remove an attacker who is already in. Review web and API access logs for requests to
j_security_checkwith encoded characters, and for API calls from unexpected source IPs that have no matching login event. - Audit state. Check for new or modified admin users, API keys and SSH keys, plus unexpected template, policy or device-configuration changes since early September.
- Rotate secrets stored on or reachable from the Manager (local credentials, integration tokens, certificates) if you find signs of compromise.
- Use Cisco’s guidance. Follow Cisco’s SD-WAN hardening guide and open a TAC case if you find indicators.
Why it matters
This is another unauthenticated path to the control plane of a WAN overlay, a class of target that has drawn repeated exploitation this year. Anyone with admin API access on the Manager can push configuration to every edge device, so a single exposed Manager can compromise an entire branch network. Treat any Manager that was internet-reachable before patching as potentially compromised until log review says otherwise.
References
- Cisco Security Advisory for CVE-2026-76504 (Cisco PSIRT, September 30, 2026)
- Rapid7 emergent threat response: CVE-2026-76504
- The Hacker News coverage
- BleepingComputer coverage
- CISA Known Exploited Vulnerabilities catalog entry, added 2026-09-30