Cisco Catalyst SD-WAN Manager Authentication Bypass CVE-2026-76504
Cisco PSIRT has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (vManage) affecting multiple release branches. The flaw arises from improper handling of URL-encoded characters within the j_security_check API endpoint, allowing unauthenticated remote attackers to bypass security controls using crafted requests, such as POST /%6a_security_check. Active exploitation has been confirmed in the wild, prompting immediate inclusion in the CISA Known Exploited Vulnerabilities catalog. Successful exploitation grants full administrative control over the SD-WAN control plane, enabling lateral movement and potential compromise of the entire managed network infrastructure. Immediate patching is required as no software workarounds are available.
- Vulnerability Mechanics: URL Encoding Bypass
- Root Cause: Identified as CWE-177 (Improper Handling of URL Encoding) within the
j_security_checkAPI path. - Exploit Vector: Attackers transmit specially crafted HTTP requests using URL-encoded characters—for example, using
%6ato represent 'j'—to evade authentication filters. -
Attack Surface: Requires no user interaction or valid credentials, facilitating fully remote, unauthenticated access.
-
Impact & Threat Landscape
- Severity: Rated CVSS v3 9.8, reflecting critical impacts on confidentiality, integrity, and availability.
- Exploitation Status: Confirmed active exploitation in the wild since September 2026; the flaw is officially listed in the CISA KEV catalog.
-
Operational Risk: Successful exploitation yields full administrative privileges over the SD-WAN control plane, allowing for the compromise of managed network devices and downstream lateral movement.
-
Detection: Indicators of Compromise (IOCs)
- Log Analysis: Inspect
/var/log/nms/containers/service-proxy/serviceproxy-access.logforPOST /%6a_security_checkHTTP requests. - Username Anomalies: Monitor
/var/log/nms/vmanage-server.logfor authentication attempts using usernames prefixed withviptela-reserved-. -
Pattern Matching: Identify any URI-encoded single characters within the
j_security_checkpath as high-fidelity indicators of exploitation attempts. -
Mitigation & Remediation
- Emergency Patching: Immediately upgrade to fixed releases: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1.
- Access Control: If immediate patching is impossible, restrict SD-WAN Manager access to trusted management networks and deploy strict filtering via a firewall or proxy.
- Incident Response: If compromise is suspected, collect
admintechfiles and open a Severity 3 TAC case with Cisco for forensic assistance.
Related posts
- threatprotect.qualys.com — Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability Exploited in Attacks (CVE-2026-76504)
- penligent.ai — CVE-2026-76504: Cisco Catalyst SD-WAN Authentication Bypass Exploited in the Wild
- Cybersecurity News — Cisco SD-WAN Manager Authentication 0-day Vulnerability Actively Exploited in the Wild
- rapid7.com — Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
- Security Affairs
- www.helpnetsecurity.com — New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
- The Hacker News — CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
- Tenable
- Sec
- Aviatrix
- Networkworld
- Ionix
- Rodtrent