← Back to Daily Briefing (#CVE202676504)

Cisco Catalyst SD-WAN Manager Authentication Bypass CVE-2026-76504

Published October 3, 2026

Cisco PSIRT has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (vManage) affecting multiple release branches. The flaw arises from improper handling of URL-encoded characters within the j_security_check API endpoint, allowing unauthenticated remote attackers to bypass security controls using crafted requests, such as POST /%6a_security_check. Active exploitation has been confirmed in the wild, prompting immediate inclusion in the CISA Known Exploited Vulnerabilities catalog. Successful exploitation grants full administrative control over the SD-WAN control plane, enabling lateral movement and potential compromise of the entire managed network infrastructure. Immediate patching is required as no software workarounds are available.

  • Vulnerability Mechanics: URL Encoding Bypass
  • Root Cause: Identified as CWE-177 (Improper Handling of URL Encoding) within the j_security_check API path.
  • Exploit Vector: Attackers transmit specially crafted HTTP requests using URL-encoded characters—for example, using %6a to represent 'j'—to evade authentication filters.
  • Attack Surface: Requires no user interaction or valid credentials, facilitating fully remote, unauthenticated access.

  • Impact & Threat Landscape

  • Severity: Rated CVSS v3 9.8, reflecting critical impacts on confidentiality, integrity, and availability.
  • Exploitation Status: Confirmed active exploitation in the wild since September 2026; the flaw is officially listed in the CISA KEV catalog.
  • Operational Risk: Successful exploitation yields full administrative privileges over the SD-WAN control plane, allowing for the compromise of managed network devices and downstream lateral movement.

  • Detection: Indicators of Compromise (IOCs)

  • Log Analysis: Inspect /var/log/nms/containers/service-proxy/serviceproxy-access.log for POST /%6a_security_check HTTP requests.
  • Username Anomalies: Monitor /var/log/nms/vmanage-server.log for authentication attempts using usernames prefixed with viptela-reserved-.
  • Pattern Matching: Identify any URI-encoded single characters within the j_security_check path as high-fidelity indicators of exploitation attempts.

  • Mitigation & Remediation

  • Emergency Patching: Immediately upgrade to fixed releases: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1.
  • Access Control: If immediate patching is impossible, restrict SD-WAN Manager access to trusted management networks and deploy strict filtering via a firewall or proxy.
  • Incident Response: If compromise is suspected, collect admintech files and open a Severity 3 TAC case with Cisco for forensic assistance.

Related posts

  1. threatprotect.qualys.com — Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability Exploited in Attacks (CVE-2026-76504)
  2. penligent.ai — CVE-2026-76504: Cisco Catalyst SD-WAN Authentication Bypass Exploited in the Wild
  3. Cybersecurity News — Cisco SD-WAN Manager Authentication 0-day Vulnerability Actively Exploited in the Wild
  4. rapid7.com — Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
  5. Security Affairs
  6. www.helpnetsecurity.com — New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
  7. The Hacker News — CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
  8. Tenable
  9. Sec
  10. Aviatrix
  11. Networkworld
  12. Ionix
  13. Rodtrent

LINK COPIED TO CLIPBOARD