Actively Exploited Authentication Bypass in Cisco Catalyst SD-WAN Manager
Security Advisory Brief
Cisco has disclosed a critical, actively exploited authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, the centralized management plane for Cisco's software-defined wide-area networking fabric. Tracked as CVE-2026-76504 and carrying a CVSS v3.1 base score of 9.8, the flaw allows an unauthenticated, remote attacker to reach the management API as the administrative user without supplying any valid credentials. Cisco published the advisory on September 30, 2026, and the same day the vulnerability was added to the CISA Known Exploited Vulnerabilities catalog with a federal remediation due date of October 3, 2026.
The root cause is improper handling of URI encoding in HTTP requests (CWE-177). Cisco Catalyst SD-WAN Manager enforces an authentication rule intended to restrict access to a specific API endpoint, but that rule can be sidestepped when the request path is submitted using percent-encoded characters. By sending a specially crafted request to the exposed API with an encoded path, an attacker causes the request to evade the protecting rule and authenticates to the API as the admin user. Cisco's detection guidance describes exploitation attempts that encode the login servlet, such as a request to the path "POST /%6a_security_check" in place of the literal "j_security_check" endpoint.
The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of its system configuration, meaning no particular feature or setting needs to be enabled for a system to be at risk. Cisco PSIRT stated that it became aware of active exploitation in September 2026, and systems with management ports exposed to the internet are at the greatest risk of compromise. Because SD-WAN Manager controls the configuration and policy of an organization's entire wide-area network, administrative access to it represents a position of substantial downstream control over connected sites and edge devices.
Threats and Vulnerabilities
CVE-2026-76504, with a CVSS v3.1 base score of 9.8, is an API authentication bypass in the session-based authentication management component of Cisco Catalyst SD-WAN Manager. The weakness stems from inconsistent handling of URI encoding: the authentication rule evaluates the encoded request path differently from the component that ultimately routes and services the request, so a path with one or more percent-encoded characters is not recognized as protected while the backend still processes it as a request to the guarded endpoint. The result is administrative access to the management API with no prior authentication, from which an attacker can alter network configuration and policy, create or modify device and user records, and establish persistence across the managed SD-WAN fabric. Cisco has confirmed active exploitation observed in September 2026 and has not published a CVSS v4.0 score; NIST has not yet issued one through the National Vulnerability Database. There is no workaround, and only fixed software releases remediate the flaw.
Client Impact
Operationally, a successful exploit grants an external attacker administrator-level control of the platform that provisions, configures, and governs an organization's entire SD-WAN estate. From that position an adversary can push malicious configuration or routing changes to edge devices, redirect or intercept traffic between sites, disable security controls, create rogue administrative accounts, and pivot deeper into both IT and operational networks that depend on the WAN fabric. For organizations that rely on SD-WAN to interconnect plants, substations, remote facilities, and data centers, compromise of the manager can translate directly into loss of network availability and integrity across geographically distributed operations. The confirmed in-the-wild exploitation and the absence of any workaround mean that exposure cannot be reduced by configuration changes alone — only patching or removing internet exposure closes the gap.
From a compliance and regulatory standpoint, the inclusion of CVE-2026-76504 in the CISA Known Exploited Vulnerabilities catalog imposes a binding remediation deadline of October 3, 2026 on U.S. federal civilian agencies under Binding Operational Directive 22-01, and KEV listing is widely treated as a baseline expectation for critical-infrastructure operators and their contractors. Organizations subject to frameworks such as NERC CIP, the NIST Cybersecurity Framework, or sector-specific regulatory programs should expect scrutiny of their patch timeliness for a critical, actively exploited flaw in a network management system. An unpatched, internet-exposed SD-WAN Manager that is subsequently compromised could also trigger breach-notification obligations and contractual security commitments to customers.
Mitigations
The following actions are recommended to reduce exposure to CVE-2026-76504 and to detect prior exploitation:
- Upgrade Cisco Catalyst SD-WAN Manager to a fixed release immediately: 20.9.10.1 for the 20.9 train, 20.12.8.2 for 20.12, 20.15.6.1 for 20.15, 20.18.4.1 for 20.18, 26.1.2.1 for 26.1, and 26.2.1 for 26.2. Releases earlier than 20.9 must be migrated to a fixed release. For Cisco-hosted cloud deployments, confirm the environment is on Cloud Release 20.15.605 or later.
- Remove Cisco Catalyst SD-WAN Manager management interfaces and APIs from direct internet exposure, and restrict access to trusted management networks and jump hosts using firewall rules and access control lists as an interim risk-reduction measure until patching is complete.
- Hunt for prior exploitation by reviewing /var/log/nms/containers/service-proxy/serviceproxy-access.log for requests to the login servlet whose path contains percent-encoded characters (for example, requests to /%6a_security_check), and inspect /var/log/nms/vmanage-server.log for entries referencing viptela-reserved- service accounts interacting with the authentication servlet.
- If exploitation indicators are found, treat the SD-WAN Manager as compromised: rotate administrative credentials and API tokens, audit all administrative accounts and recent configuration changes for unauthorized modifications, and review managed edge-device configurations for tampering before restoring normal operations.
- Enforce multi-factor authentication for administrative access where supported, monitor for anomalous API activity and configuration changes going forward, and subscribe to Cisco PSIRT notifications so future advisories affecting the SD-WAN platform are actioned promptly.
Applying the vendor-provided fixed release is the only complete remediation; the network-restriction and monitoring steps reduce risk and surface prior intrusions but do not remove the underlying vulnerability.
1898 & Co. Response
1898 & Co. works alongside asset owners and operators to reduce exposure to actively exploited vulnerabilities affecting the network infrastructure that underpins both IT and operational environments. Our teams have supported organizations across critical-infrastructure sectors in inventorying internet-facing management systems, prioritizing emergency patching for KEV-listed flaws, and validating that remediation has been applied across distributed SD-WAN and edge estates.
For a vulnerability of this severity, 1898 & Co. can assist clients in rapidly identifying exposed Cisco Catalyst SD-WAN Manager instances, reviewing the detection artifacts described in this advisory for signs of prior compromise, and scoping incident response where exploitation is suspected. This work draws on hands-on experience with OT and IT network architectures and with the operational constraints that govern how and when critical network management systems can be patched.
Through managed threat hunting, vulnerability management, and incident response services, 1898 & Co. helps clients move from advisory awareness to verified remediation. Our approach is designed to align technical remediation with the compliance obligations that accompany KEV-listed vulnerabilities, so that security leaders can demonstrate timely, evidence-based action to regulators, customers, and internal stakeholders.