---
title: "Threat Hunt Plan: Cisco Catalyst SD-WAN Manager API Authentication Bypass — Hunting Exploitation of an Actively-Exploited Zero-Day"
description: This hunt seeks evidence of attempted or successful exploitation of CVE-2026-76504, an unauthenticated API authentication bypass in Cisco Catalyst SD-WAN Manager (formerly vManage) that Cisco PSIRT confirmed as actively exploited in September 2026.
---

[Advisories | 1898 & Co.](https://1898advisories.burnsmcd.com)

# [Threat Hunt Plan: Cisco Catalyst SD-WAN Manager API Authentication Bypass — Hunting Exploitation of an Actively-Exploited Zero-Day](https://1898advisories.burnsmcd.com/threat-hunt-plan-cisco-catalyst-sd-wan-manager-api-authentication-bypass-hunting-exploitation-of-an-actively-exploited-zero-day)

 Written by [The 1898 & Co. Team](https://1898advisories.burnsmcd.com/author/1898-co-team) | October 8, 2026

Date: 2026-10-02 | Revision 1.3

#### Hunt Objective and Scope

This hunt seeks evidence of attempted or successful exploitation of CVE-2026-76504, an unauthenticated API authentication bypass in Cisco Catalyst SD-WAN Manager (formerly vManage) that Cisco PSIRT confirmed as actively exploited in September 2026. The flaw stems from improper handling of URI encoding (CWE-177): a percent-encoded request path evades the authentication rule protecting the login servlet (j\_security\_check) while the backend still services it, granting an unauthenticated remote attacker administrative access to the management API.

In scope: all Cisco Catalyst SD-WAN Manager instances (on-premises and Cisco-hosted cloud), the networks and jump hosts from which the manager is administered, the manager's own forwarded application logs (service-proxy access log and vmanage-server log), and the external-facing surface of the management plane. Because SD-WAN Manager provisions and governs the wide-area fabric that interconnects data centers, remote sites, and — in many deployments — operational-technology (OT) locations, the hunt extends to downstream edge-device configuration integrity where the fabric reaches OT networks.

Time window: from the earliest known exploitation, not the disclosure date. Cisco PSIRT became aware of active exploitation in September 2026, so the window starts September 1, 2026 and extends backward wherever retention allows. The external-exposure hypothesis (Hypothesis 1) is executed FIRST; its output defines the priority target population — any internet-reachable in-range instance is hunted exhaustively by the internal hypotheses.

Data floor (pre-flight, before any leg runs): a time picker is not retention. For each telemetry family, measure the oldest retained event and record the floor date. Report the part of the window before the floor as Non-Conclusive, never clean.

`#event_simpleName=/^(NetworkConnectIP4|NetworkReceiveAcceptIP4|UserLogon|ProcessRollup2)$/ | groupBy([#event_simpleName], function=min(@timestamp, as=oldest), limit=max)`

 

Do the same for the manager's forwarded syslog in Datadog (the earliest \`source:syslog\` event from the manager host) and for any PCAP store. Hypotheses 2 and 4 are event-based, so they are bounded by the floor. Hypothesis 3 is partly state-based: the accounts and configuration that exist now can be listed directly on the manager, regardless of log retention.

Matching note that governs every leg below: the published indicator is the ENCODED form of the servlet path (POST /%6a\_security\_check). An encoded request line does not contain the literal string j\_security\_check, so any query that requires both "j\_security\_check" and an encoded character returns zero on exactly the published indicator. Every detection here keys on the shared suffix "security\_check" plus the presence of a percent-encoding, or on a normalized-versus-raw path mismatch.

#### Hypotheses and Hunt Procedures

**Hypothesis 1:** An external actor can reach an internet-facing instance of Cisco Catalyst SD-WAN Manager, observable as an exposed management/web service in passive internet-scan indices. Execute FIRST; its output scopes the internal hypotheses.

**MITRE ATT&CK:** Reconnaissance | T1595 — Active Scanning | defender-side passive discovery of the exposed management plane an actor would enumerate. Initial Access | T1133 — External Remote Services | the exposed manager API is the attacker's entry point. ICS | T0883 — Internet Accessible Device | relevant where the manager governs fabric reaching OT sites.

**Verdict criteria:** Positive — an owned, two-engine-corroborated SD-WAN Manager login interface on a public IP; Negative — no owned hit across the full public IP inventory AND the unscoped control returns a non-zero population; Non-Conclusive — the unscoped control returns 0, or part of the inventory was not searched (first page only, rate-limited, no API key); missing coverage prevents determining exposure for those ranges.

**Control** — unscoped population: run each title query unscoped first and record the count. A filter that matches nothing unscoped is unvalidated, so its scoped zero means nothing. Also record whether results were paged to completion, since a first page only is truncated. Treat hits that the engines tag as honeypots, or that sit on scanner-heavy ranges, as unattributed until the ownership signals agree.

**Collection Queries** — passive external indices (STRICTLY passive; never probe target infrastructure):

Author queries unscoped first to prove the filter matches the product, then scope to owned ranges. The login page title differs by release (older releases present "vManage", releases after the Catalyst rebrand present "Catalyst SD-WAN"), so run both title forms; keep whichever form returns a non-zero unscoped population, and treat a title form that returns zero unscoped as an unvalidated filter, not as absence. API keys are referenced by env-var name only (SHODAN\_API\_KEY, CENSYS\_API\_SECRET, CENSYS\_ORG\_ID, NETLAS\_API\_KEY).

`Shodan: http.title:"vManage"`

 

`http.title:"Catalyst SD-WAN"`

 

`http.title:"vManage" net:<your_public_CIDR>`

 

`http.title:"vManage" org:"<Your Org Name>"`

 

`http.title:"vManage" asn:AS<your_ASN>`

 

`// vuln: filter is paid-tier only; else match the version banner against the advisory range vuln:CVE-2026-76504`

 

`Censys (CenQL — host.services.* form; the legacy services.* form 403s on free plans and returns zero rows when crossed): host.services.endpoints.http.html_title: "vManage"`

 

`host.services.endpoints.http.html_title: "Catalyst SD-WAN"`

 

`host.services: (port = "443" and endpoints.http.html_title: "vManage")`

 

`host.services.endpoints.http.html_title: "vManage" and (host.autonomous_system.asn = <your_ASN> or host.ip: "<your_public_CIDR>")`

 

`Netlas: http.title:"vManage"`

 

`http.title:"Catalyst SD-WAN"`

 

`http.title:"vManage" AND host:<your_public_CIDR>`

 

`→ Cross-reference every exposed instance + version banner against the CISA Known Exploited Vulnerabilities catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog) and CVE-2026-76504; a KEV match on an in-range instance is presumptive actor-associated initial-access risk.`

 

**Analysis Queries:**

`- Attribute each hit with at least two independent ownership signals (PTR, ASN, certificate CN/SAN, WHOIS/RDAP, own cloud inventory) before reporting; an unattributable hit on shared hosting or CDN is inconclusive, not negative. - Version-triage each banner against the advisory's affected trains (all releases prior to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1), and record the index scan timestamp — a fixed-version banner predating the window is not evidence of safety. - Corroborate in at least two of Shodan / Censys / Netlas before escalating; absence from one index is evidence only that that index did not observe the host. - Historical pivot — establish whether the exposure spans the September 2026 exploitation window; continuous exposure across it means the host was presumptively enumerated. - Pivot into the internal hypotheses — feed every confirmed-owned in-range instance in as a priority target and hunt it exhaustively. Where the manager governs fabric reaching OT workloads, document the blast radius: internet reachability of infrastructure serving a control environment is a finding in its own right under IEC 62443 and NERC CIP, independent of confirmed exploitation.`

 

`Favicon-hash pivoting (for stripped banners / non-standard mgmt ports): derive the hash passively from an instance you own by reusing an index-computed value — never fetch /favicon.ico from a target, never copy a hash from a third-party write-up.`

 

**Hypothesis 2:** An unauthenticated attacker has attempted or achieved the authentication bypass against an internet-facing SD-WAN Manager, observable as requests to the login servlet whose path contains percent-encoded characters (for example POST /%6a\_security\_check in place of /j\_security\_check) in the manager's service-proxy access log and vmanage-server log.

**MITRE ATT&CK:** Initial Access | T1190 — Exploit Public-Facing Application | the encoded-path request bypasses the servlet authentication rule to reach the API. Defense Evasion | T1027 — Obfuscated Files or Information | percent-encoding of the servlet name is the evasion primitive.

**Verdict criteria:** Positive — a servlet request whose path is not the canonical literal (encoded) and was serviced (200/302), or a viptela-reserved- account on the same line as the servlet; Negative — no such entry across the window AND the Datadog control returns ordinary logins AND the data floor precedes the window start; Non-Conclusive — the control returns 0, or appliance syslog is not forwarded; missing parsed servlet paths prevents determining whether the bypass was attempted.

**Control** — telemetry presence: the Datadog control query below (ordinary \`/j\_security\_check\` logins must return rows) proves that the path attribute is parsed. For the CQL legs, prove the family is present on the same scope:

`#event_simpleName=NetworkConnectIP4 | RemotePort = 443 | cidr(RemoteAddressIP4, subnet=["10.100.0.0/24"]) | head(1)`

 

Primary telemetry note / data-source gap: Cisco Catalyst SD-WAN Manager is an appliance that does not run the CrowdStrike Falcon sensor, so the authoritative artifacts are its own application logs forwarded to the SIEM/Datadog (service-proxy access log, vmanage-server log). The CrowdStrike CQL legs below hunt the surrounding fleet (jump hosts, admin workstations, any Falcon-instrumented reverse proxy fronting the manager), not the appliance itself, and an external attacker's own host is never Falcon-instrumented. Where appliance syslog is NOT forwarded, this is a collection gap — remediate by enabling remote logging on the manager before relying on a negative result.

**Datadog Log Search** — appliance forwarded logs (manager syslog). Run the control query FIRST:

`source:syslog @http.url_details.path:"/j_security_check" // time range: 2026-09-01T00:00Z to current // CONTROL — ordinary logins must return rows; zero means the path attribute is not parsed (a collection gap), not a clean result`

 

`source:syslog @http.url_details.path:*security_check* -@http.url_details.path:"/j_security_check" // time range: 2026-09-01T00:00Z to current // any servlet path that is NOT the canonical literal — catches /%6a_security_check and other encodings of the leading characters // requires the path to be stored undecoded; if the control shows decoded paths only, fall back to the raw-message search below`

 

→ Expected Positive shape: rows whose path reads \`/%6a\_security\_check\` (or another encoding) with status 200, from a client IP outside the approved admin range — the shape of Cisco's published serviceproxy-access.log example.

`source:syslog "security_check" "%6a" // time range: 2026-09-01T00:00Z to current // raw-message fallback for the published encoded form when the path attribute is unavailable; Datadog full-text matching is token-based, so prove it with one known test line containing /%6a_security_check before trusting a zero`

 

`source:syslog "security_check" "viptela-reserved-" // time range: 2026-09-01T00:00Z to current // reserved-service-account access to the auth servlet in vmanage-server.log — the published post-bypass indicator; the log records the ENCODED path, so match the suffix, never the literal j_security_check`

 

**Datadog Live Process Monitoring is not applicable to the appliance** (no Datadog Agent on the manager); use the syslog searches above as the authoritative source.

**CrowdStrike Falcon LogScale** (CQL) — internal hosts connecting to the manager web port (who administers the manager; reverse proxy / jump host):

`#event_simpleName=NetworkConnectIP4 | RemotePort = 443 | cidr(RemoteAddressIP4, subnet=["10.100.0.0/24"]) | groupBy([aid, ComputerName, LocalAddressIP4], function=count(), limit=100000)`

 

`#event_simpleName=NetworkConnectIP4 | RemotePort = 443 | cidr(RemoteAddressIP4, subnet=["10.100.0.0/24"]) | !cidr(LocalAddressIP4, subnet=["10.20.0.0/24"]) | table([@timestamp, aid, ComputerName, LocalAddressIP4, RemoteAddressIP4, RemotePort], limit=20000) // 10.100.0.0/24 = illustrative manager management subnet; 10.20.0.0/24 = illustrative approved admin subnet — substitute your own`

 

**BPF packet capture** — rolling capture of management-plane HTTPS at the manager's upstream tap:

`tcpdump -i eth0 -s 0 -w /captures/sdwan_mgmt_%Y%m%d_%H%M%S.pcap -G 3600 -C 500 '(tcp port 443 and host 10.100.0.10) or (vlan and tcp port 443 and host 10.100.0.10)' // VLAN two-branch form: on a tagged trunk an untagged filter captures 0 frames // -G 3600 rotates hourly (strftime pattern in -w name required), -C 500 caps each file at ~500 MB; 10.100.0.10 = illustrative manager IP // management traffic is TLS: URI-level analysis of these captures requires the session keys or a TLS-terminating proxy; without them a capture yields flow metadata only`

 

**YARA file-system scan** — manager appliance log/dropped-artifact scan where shell access is available (run read-only against a forensic copy):

`yara -r rules/sdwan_authbypass.yar /var/log/nms/ >> hits_sdwan.txt`

 

**Analysis Queries:**

**Datadog Log Analytics** — encoded-servlet request rate and source attribution:

`source:syslog @http.url_details.path:*security_check* -@http.url_details.path:"/j_security_check" // Use Timeseries view; group by @network.client.ip; time range 2026-09-01T00:00Z to current`

 

`source:syslog "security_check" "viptela-reserved-" // Use Table view; group by @network.client.ip, @usr.name; time range 2026-09-01T00:00Z to current`

 

**Datadog Monitor** (log alert — encoded auth-bypass attempt):

`Type: Log Alert Query: source:syslog @http.url_details.path:*security_check* -@http.url_details.path:"/j_security_check" Evaluation window: last 5 minutes Alert condition: count > 0 Message: "ALERT: Non-canonical security_check path on SD-WAN Manager — possible CVE-2026-76504 exploitation; investigate source IP immediately @soc-pagerduty" Prerequisites: Cisco Catalyst SD-WAN Manager service-proxy access log and vmanage-server log forwarded to Datadog as source:syslog with @network.client.ip and an undecoded @http.url_details.path parsed (validated by the control query above)`

 

**Wireshark / tshark** — isolate encoded login-servlet requests in decrypted management traffic (Wireshark http.request.uri is the raw, undecoded URI):

`tshark -r sdwan_mgmt.pcap -o tls.keylog_file:sslkeys.log -Y 'http.request.uri contains "security_check" and http.request.uri contains "%"' -T fields -e frame.time -e ip.src -e ip.dst -e http.request.method -e http.request.uri // Wireshark display-filter equivalent: http.request.uri contains "security_check" && http.request.uri matches "%[0-9a-fA-F]{2}"`

 

**CrowdStrike Falcon LogScale** (CQL) — rarest internal hosts reaching the manager web port (an unfamiliar administering host is the lead):

`#event_simpleName=NetworkConnectIP4 | RemotePort = 443 | cidr(RemoteAddressIP4, subnet=["10.100.0.0/24"]) | groupBy([ComputerName, LocalAddressIP4], function=count(), limit=100000) | sort(_count, order=asc, limit=50)`

 

**Hypothesis 3:** Following a successful bypass, an attacker has used administrative API access to create or modify accounts and alter manager configuration, observable as anomalous admin-session activity, new or modified user records (including viptela-reserved- service accounts), and configuration changes outside approved change windows.

**MITRE ATT&CK:** Persistence | T1136 — Create Account | an attacker with admin API access provisions durable accounts. Persistence / Privilege Escalation | T1098 — Account Manipulation | modification of existing admin or service accounts. Impact | T1565 — Data Manipulation | unauthorized configuration/policy changes pushed through the manager.

**Verdict criteria:** Positive — an account created or modified, or a configuration or template pushed, with no matching change record, or reserved-account activity; Negative — every account change and push reconciles to a change record AND the field-presence control returns rows; Non-Conclusive — the manager's logs carry no parsed user field; missing user attribution prevents determining who made the changes.

**Control** — field presence (a family control does not cover a field filter): the account queries filter on \`@usr.name\`, so first prove that the field is populated in the window.

`source:syslog host:<sdwan_manager_hostname> @usr.name:* // time range: 2026-09-01T00:00Z to current`

 

State-based check (independent of log retention): list the current users and roles on the manager (Administration \> Manage Users) and compare them against the approved administrator roster. An account that exists now and has no change record is a finding, whatever the log floor.

**Datadog Log Search** — admin-session and account activity on the manager:

`source:syslog @usr.name:viptela-reserved-* // time range: 2026-09-01T00:00Z to current // any reserved-service-account activity — correlate with the servlet search in Hypothesis 2 before escalating`

 

`source:syslog ("add user" OR "create user" OR "user added" OR "aaa" OR "role") -@usr.name:(<approved_admin_1> OR <approved_admin_2>) // time range: 2026-09-01T00:00Z to current // account/role changes not attributable to an approved administrator`

 

`source:syslog ("template" OR "device config" OR "push configuration" OR "config-push") @evt.outcome:success // time range: 2026-09-01T00:00Z to current // configuration/template pushes — correlate against the change calendar`

 

**Datadog Audit Trail** — defense-evasion check on the Datadog side (Audit Trail records Datadog platform activity, not SD-WAN console logins): changes to the monitors or log pipelines that carry the manager's logs:

`source:datadog @evt.name:Monitor @action:(modified OR deleted) // time range: 2026-09-01T00:00Z to current`

 

**Windows Event Log** — admin workstations and jump hosts used to reach the manager (collect, then hunt):

`Windows Event ID 4624 (successful logon) / 4625 (failed logon) — on jump hosts, to timeline who accessed the manager console Windows Event ID 4688 (process creation) — browser or API-client (curl, Postman, python) launches targeting the manager IP PowerShell collection: Get-WinEvent -FilterHashtable @{LogName='Security';Id=4688;StartTime=(Get-Date '2026-09-01')} | Where-Object { $_.Message -match 'curl|python|Invoke-RestMethod|postman' } | Export-Csv -NoTypeInformation jumphost_apiclients.csv`

 

**Analysis Queries:**

**Datadog Log Analytics** — new/modified accounts over the window:

`source:syslog ("add user" OR "create user" OR "user added" OR "role") // Use Table view; group by @usr.name, @network.client.ip; time range 2026-09-01T00:00Z to current`

 

**Datadog Monitor** (log alert — reserved-account activity):

`Type: Log Alert Query: source:syslog "security_check" "viptela-reserved-" Evaluation window: last 5 minutes Alert condition: count > 0 Message: "ALERT: viptela-reserved- service account against the auth servlet on SD-WAN Manager — presumptive CVE-2026-76504 post-exploitation @soc-pagerduty" Prerequisites: vmanage-server log forwarded as source:syslog`

 

**OT Data Collection: Claroty xDome** — where the SD-WAN fabric reaches OT, export the device inventory and new-flow activity for edge sites governed by the affected manager and diff against the sanctioned baseline to surface configuration-driven changes in OT communication.

**OT Data Collection: Dragos Platform** — review detections and notifications for the edge/OT boundary sites during the hunt window for new or anomalous flows that could follow an unauthorized configuration push.

**Hypothesis 4:** An attacker has leveraged the compromised SD-WAN Manager to pivot into connected IT/OT networks or stage tooling, observable as inbound connections from the manager's management IP to internal hosts and credential-access or lateral-movement activity on reachable hosts.

**MITRE ATT&CK:** Lateral Movement | T1021 — Remote Services | the manager's trusted position is used to reach downstream hosts. Credential Access | T1003 — OS Credential Dumping | tooling staged on reachable Windows hosts to harvest credentials for deeper movement. Credential Access / Lateral Movement | T1078 — Valid Accounts | credentials held by or captured on the appliance are reused from its own address.

**Verdict criteria:** Positive — an accepted remote-service connection or an interactive/network logon that originates from the manager's management IP to an internal or OT host and is not a documented integration, or a credential-dump YARA hit on a reachable host; Negative — none across the window AND both family controls return rows; Non-Conclusive — a control returns 0, or the reachable hosts carry no Falcon sensor; missing receive-side telemetry prevents determining whether the manager was used as a pivot.

**Control** — family presence on the receiving hosts (both events must exist before their zero means anything):

`#event_simpleName=NetworkReceiveAcceptIP4 | head(1)`

 

`#event_simpleName=UserLogon | head(1)`

 

**Intel-driven leg** — the appliance as credential source: the threat-actor KB documents a pattern for edge-appliance intrusions in which the appliance is the credential source, not just the door. The readable signal is authentications that originate from the appliance's own address into internal or OT segments, and the KB lists SD-WAN orchestrators as a precondition for that pattern. Hunt the logons, not only the connections:

`#event_simpleName=UserLogon | cidr(RemoteAddressIP4, subnet=["10.100.0.0/24"]) | groupBy([ComputerName, UserName, LogonType, RemoteAddressIP4], function=count(as=cnt), limit=100000)`

 

→ Expected Positive shape: logons on internal or OT hosts whose source address is the manager's, by an account that does not belong to a documented integration, especially LogonType 3 or 10.

`Get-WinEvent -FilterHashtable @{LogName='Security';Id=4624;StartTime=(Get-Date '2026-09-01')} | Where-Object { $_.Message -match 'Source Network Address:\s+10\.100\.0\.' } | Export-Csv -NoTypeInformation logons_from_manager.csv`

 

Direction note: NetworkConnectIP4 records connections a Falcon host INITIATES, so RemoteAddressIP4 = manager on that event means host-to-manager (Hypothesis 2). A connection FROM the manager is recorded on the receiving Falcon host as NetworkReceiveAcceptIP4, where RemoteAddressIP4 is the manager and LocalPort is the service it reached.

**CrowdStrike Falcon LogScale** (CQL) — accepted inbound connections FROM the manager management IP on remote-service ports (the manager as a pivot source):

`#event_simpleName=NetworkReceiveAcceptIP4 | cidr(RemoteAddressIP4, subnet=["10.100.0.0/24"]) | in(LocalPort, values=["22","135","445","3389","5985","5986"]) | table([@timestamp, aid, ComputerName, LocalAddressIP4, LocalPort, RemoteAddressIP4], limit=20000)`

 

→ Expected Positive shape: rows where the manager's address reached SMB (445), RDP (3389), WinRM (5985/5986) or SSH (22) on a host that no documented integration explains.

**YARA process-memory scan** — reachable Windows hosts, credential-dumping tooling in ANY process (the tool's strings live in the tool's process, not in lsass; classic YARA 4.5, PID is the positional target, no -p flag):

`yara rules/cred_dump.yar <pid> // bulk enumeration: Get-Process | ForEach-Object { yara rules/cred_dump.yar $_.Id 2>$null } | Out-File -Append hits_cred.txt // CrowdStrike Falcon RTR can execute this remotely on reachable hosts; SeDebugPrivilege required`

 

**Analysis Queries:**

**CrowdStrike Falcon LogScale** (CQL) — fan-out from the manager IP: which hosts and services it reached, rarest first:

`#event_simpleName=NetworkReceiveAcceptIP4 | cidr(RemoteAddressIP4, subnet=["10.100.0.0/24"]) | groupBy([ComputerName, LocalAddressIP4, LocalPort], function=count(), limit=100000) | sort(_count, order=asc, limit=50)`

 

**Datadog Log Search** — outbound from the manager to unexpected external destinations (C2 / exfil staging):

`source:syslog host:<sdwan_manager_hostname> @network.destination.ip:* -@network.destination.ip:10.* -@network.destination.ip:172.16.* -@network.destination.ip:192.168.* // time range: 2026-09-01T00:00Z to current // outbound from the manager to a non-RFC1918 destination warrants review; @network.destination.ip:* is required — without it, every log lacking the attribute satisfies the negations`

 

**Datadog Monitor** (log alert — manager outbound to public IP):

`Type: Log Alert Query: source:syslog host:<sdwan_manager_hostname> @network.destination.ip:* -@network.destination.ip:10.* -@network.destination.ip:172.16.* -@network.destination.ip:192.168.* Evaluation window: last 15 minutes Alert condition: count > 0 Message: "ALERT: SD-WAN Manager outbound connection to a public IP — possible post-exploitation C2/exfil @soc-pagerduty" Prerequisites: manager flow/connection logs forwarded as source:syslog with @network.destination.ip parsed`

 

#### Threat Actor Profile

Cisco PSIRT confirmed active exploitation in September 2026 but has not attributed the activity to a named group. The profile best fitting a pre-disclosure zero-day against an internet-facing network-management appliance is an opportunistic-to-sophisticated actor: capable of weaponizing a URI-encoding bypass, enumerating exposed vManage instances at scale, and operationalizing administrative control of the WAN fabric. Access path is direct — an unauthenticated HTTPS request to an internet-exposed management API, requiring no credentials, no user interaction, and no particular manager configuration. TTPs center on exploitation of a public-facing application (T1190), encoded-request evasion (T1027), account creation and manipulation for persistence (T1136/T1098), and abuse of the manager's trusted position for lateral movement (T1021) and configuration impact (T1565). CVE-2026-76504 was added to CISA KEV on the disclosure date; KEV listing confirms exploitation, not attribution, and the KEV entry records ransomware use as "Unknown". The threat-actor KB's attribution caveats apply to any later naming: write "activity consistent with \<group\> (per \<source\>)", never a firm attribution. Its edge-appliance pattern (the appliance as credential source, which the KB lists SD-WAN orchestrators as a precondition for) is why Hypothesis 4 hunts logons that originate from the manager. Critical-infrastructure operators whose SD-WAN fabric reaches OT sites should still treat a confirmed compromise as a potential precursor to operational disruption.

#### Data Sources Required

**Network:** management-plane PCAP / tap upstream of the SD-WAN Manager (URI-level analysis requires TLS session keys or a TLS-terminating proxy), NetFlow and firewall logs covering the management VLAN and any internet-facing path to the manager, reverse-proxy access logs where a proxy fronts the manager.

**Endpoint:** CrowdStrike Falcon telemetry from jump hosts, admin workstations, and any Falcon-instrumented proxy serving the manager (the appliance itself does not run Falcon); Windows Security and Sysmon logs from those hosts.

Appliance / vendor logs (authoritative for this hunt): Cisco Catalyst SD-WAN Manager service-proxy access log (/var/log/nms/containers/service-proxy/serviceproxy-access.log) and vmanage-server log (/var/log/nms/vmanage-server.log), forwarded to the SIEM/Datadog with the request path stored undecoded; AAA and audit logs from the manager.

**OT/ICS:** where the SD-WAN fabric reaches OT sites, the OT monitoring platform inventory and flow data (Claroty xDome, Dragos Platform) for edge-device configuration and new-flow review, plus historian/alarm correlation for any operational anomaly coincident with a configuration push.

External attack surface: the passive internet-scan indices queried read-only (Shodan / Censys / Netlas), the CISA Known Exploited Vulnerabilities catalog, and the organization's authoritative public IP and cloud asset inventories — the last of which is required for attribution of any exposed instance and without which the exposure determination cannot be completed.

#### Detection Signatures

**SIGMA Rule 1** — percent-encoded login-servlet path in web/proxy logs (logsource category: webserver). The selection keys on the suffix "security\_check" plus any percent-encoding in the same path, so it matches the published /%6a\_security\_check form; encodings placed inside "security\_check" itself are covered by Snort/Suricata Rule 1.

`title: Cisco SD-WAN Manager Encoded security_check Auth Bypass Attempt id: 7b1c9e24-2f3a-4d6b-9a1e-5c8d0f2a4b6e status: experimental description: Detects requests to the login servlet whose path contains a percent-encoded character, the CVE-2026-76504 authentication-bypass primitive. references: - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU author: 1898 & Co. date: 2026-10-02 logsource: category: webserver detection: sel_path: cs-uri-stem|contains: 'security_check' sel_encoded: cs-uri-stem|re: '%[0-9a-fA-F]{2}' condition: sel_path and sel_encoded falsepositives: - Legitimate clients do not percent-encode the static servlet path; near-zero expected. Requires the log source to record the path undecoded. level: high tags: - attack.initial_access - attack.t1190`

 

**SIGMA Rule 2** — reserved service-account activity on the manager (logsource product: linux, service: syslog):

`title: Cisco SD-WAN Manager Reserved Service-Account Activity id: 3d5f8a10-6c2b-4e9d-8f71-0a2c4e6b8d1f status: experimental description: Detects activity by viptela-reserved- service accounts against the authentication servlet, a published CVE-2026-76504 post-exploitation indicator. references: - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU author: 1898 & Co. date: 2026-10-02 logsource: product: linux service: syslog detection: sel: message|contains: 'viptela-reserved-' sel_ctx: message|contains: 'security_check' condition: sel and sel_ctx falsepositives: - None expected; reserved accounts should not authenticate via the external servlet path level: critical tags: - attack.persistence - attack.t1098`

 

**SIGMA Rule 3** — API client launched from a jump host toward the manager servlet (logsource category: process\_creation):

`title: Command-line API Client Targeting SD-WAN Manager Login Servlet id: 9e0b2d46-8a1c-4f7e-b3d5-2c6e8a0f4b1d status: experimental description: Detects curl / python / PowerShell invocations referencing the SD-WAN Manager login servlet, in plain or encoded form, as used to drive the bypassed API. author: 1898 & Co. date: 2026-10-02 logsource: category: process_creation product: windows detection: sel_proc: Image|endswith: - '\curl.exe' - '\python.exe' - '\powershell.exe' sel_target: CommandLine|contains: 'security_check' condition: sel_proc and sel_target falsepositives: - Sanctioned automation that drives the manager API from an approved host; allowlist by host and user level: medium tags: - attack.execution - attack.t1190`

 

**Snort/Suricata rules** (Suricata 8 syntax). Suricata's http.uri buffer is NORMALIZED — percent-decoding is applied — so a %XX pattern can never match in it. These rules use that to their advantage: the normalized URI contains /j\_security\_check while the raw URI (http.uri.raw) does not, which is true only when some part of the servlet path was encoded, wherever the encoding sits. The management plane is HTTPS, so these rules fire only on a sensor that sees decrypted traffic (TLS-terminating proxy, load balancer mirror, or key-assisted decryption); on an encrypted-only tap they are silent by construction, and a clean result from such a sensor is not a negative.

**Snort/Suricata Rule 1** — encoded login-servlet request (normalized path matches, raw path does not):

`alert http any any -> $HOME_NET any (msg:"1898 CISCO SD-WAN Manager encoded j_security_check auth bypass CVE-2026-76504"; flow:to_server,established; http.uri; content:"/j_security_check"; nocase; http.uri.raw; content:!"/j_security_check"; nocase; flowbits:set,sdwan.encbypass; classtype:web-application-attack; reference:cve,2026-76504; sid:1000001; rev:2;)`

 

**Snort/Suricata Rule 2** — the encoded request was SERVICED (200 OK or a 302 login redirect) rather than rejected; matching the success codes, not "anything but 401/403", keeps 404 and 5xx responses from alerting:

`alert http $HOME_NET any -> any any (msg:"1898 CISCO SD-WAN Manager encoded j_security_check request accepted - probable successful bypass CVE-2026-76504"; flow:to_client,established; flowbits:isset,sdwan.encbypass; http.stat_code; pcre:"/^(200|302)$/"; classtype:successful-admin; reference:cve,2026-76504; sid:1000002; rev:3;)`

 

**YARA Rule 1 targets on-disk log artifacts of the exploitation attempt on a forensic copy of /var/log/nms. YARA matches across a whole file rather than per line, so each string is self-contained:** the encoded-servlet regexes match the encoded request line on its own (an encoded line does not contain the literal /j\_security\_check, so that literal is never required), and the reserved-account string is a single-line regex binding viptela-reserved- to the servlet name within the same line, so a reserved account merely appearing somewhere in a busy log does not fire. $enc1 is the published /%6a form; $enc2 covers an encoding anywhere before "security\_check"; $enc3 covers an encoding inside it.

`rule SDWAN_AuthBypass_Log_Artifacts { meta: description = "CVE-2026-76504 encoded security_check request and viptela-reserved- servlet access in SD-WAN Manager logs" author = "1898 & Co." date = "2026-10-02" reference = "cisco-sa-sdwan-webauth-xr8beuuU" strings: $enc1 = /\/%6[aA]_security_check/ // published encoded form (%6a = 'j') $enc2 = /\/[A-Za-z0-9_%]{0,4}%[0-9A-Fa-f]{2}[A-Za-z0-9_%]{0,4}security_check/ // encoding before the suffix $enc3 = /\/j_[A-Za-z_%0-9]{0,30}%[0-9A-Fa-f]{2}[A-Za-z_%0-9]{0,30}check/ // encoding inside "security_check" $svc = /viptela-reserved-[^\n]{0,300}security_check|security_check[^\n]{0,300}viptela-reserved-/ // same-line reserved-account servlet access condition: any of them }`

 

**YARA Rule 2 targets credential-dumping tooling in the process memory of Windows hosts reachable from the compromised manager, covering the standard lateral-movement follow-on; it is scoped to Windows hosts and is run against every process, since the tool's strings reside in the tool's own process. Each branch keys on a distinct tool's in-memory signature, and a fifth catch-all branch requires a memory-read API string together with lsass.exe and at least one tool indicator so that unknown wrappers still surface; the lsass.exe co-requirement suppresses matches on benign binaries that merely contain one API name.**

`rule Credential_Dump_Tool_Memory_Artifacts { meta: description = "Credential-dumping tooling in process memory on hosts reachable from a compromised SD-WAN Manager (T1003)" author = "1898 & Co." date = "2026-10-02" strings: $mimi1 = "sekurlsa::logonpasswords" ascii nocase $mimi2 = "lsadump::sam" ascii nocase $mimi3 = "privilege::debug" ascii nocase $mimi4 = "mimikatz" ascii nocase $mimih = { 6D 69 6D 69 6B 61 74 7A } // "mimikatz" hex $wce1 = "wce.exe" ascii nocase $gsec = "gsecdump" ascii nocase $com1 = "MiniDump" ascii nocase $com2 = "comsvcs" ascii nocase $lsass = "lsass.exe" ascii nocase $api1 = "NtReadVirtualMemory" ascii nocase $api2 = "ReadProcessMemory" ascii nocase condition: any of ($mimi*) or ($wce1 and $lsass) or $gsec or ($com1 and $com2 and $lsass) or (($api1 or $api2) and $lsass and ($mimi4 or $wce1 or $gsec)) }`

 

#### Indicators of Compromise

Network IoCs: HTTP/HTTPS requests to the management port whose login-servlet path contains a percent-encoding (POST /%6a\_security\_check and variants where any character of j\_security\_check is encoded); such a request that is serviced rather than met with a 401/403 rejection; outbound connections from the manager management IP to non-RFC1918 destinations.

Pivot IoCs: an interactive or network logon on an internal or OT host whose source address is the manager's management IP, by an account no documented integration explains.

Host / appliance IoCs: entries in /var/log/nms/containers/service-proxy/serviceproxy-access.log showing an encoded security\_check request; entries in /var/log/nms/vmanage-server.log referencing viptela-reserved- service accounts interacting with the authentication servlet; newly created or modified administrative/service accounts on the manager with no change-record; configuration or device-template pushes outside the approved change window.

External-exposure IoCs: a Cisco Catalyst SD-WAN Manager / vManage login interface observed on an owned public IP in Shodan / Censys / Netlas, especially one whose version banner falls in an affected train and whose exposure spans the September 2026 window.

OT / operational IoCs (behavioral, scoped to this hunt): new or altered communication flows at SD-WAN edge sites serving OT networks coincident with a manager configuration push; edge-device configuration drift from the sanctioned baseline on the OT monitoring platform.

#### False Positive Baseline

1\. Sanctioned automation or orchestration that drives the SD-WAN Manager API from an approved jump host/service account — allowlist by source IP and account, then investigate only the residual.

2\. Legitimate administrator logons to the manager console from the approved admin CIDR during business hours — baseline the approved admin source ranges before flagging a source as anomalous.

3\. Scheduled device-template and configuration pushes performed within the documented change window — correlate every config-push hit against the change calendar.

4\. Vulnerability scanners and approved external attack-surface tooling probing the management port — these can generate encoded servlet requests but originate from known scanner IPs; allowlist them, and treat a scanner request that was serviced (Snort/Suricata Rule 2) as a finding regardless of source.

5\. Monitoring, backup, and health-check service accounts that legitimately appear in the manager logs — distinguish these from viptela-reserved- reserved accounts, which should never authenticate via the external servlet path.

6\. EASM misattribution — a vManage login interface on shared hosting, a CDN, or a provider ASN that is not actually the organization's asset; require two independent ownership anchors before treating an exposed instance as owned (a provider ASN alone is not an attribution anchor).

#### Escalation Criteria

1\. Any service-proxy or vmanage-server log entry showing an encoded security\_check request that was serviced rather than rejected — treat the manager as presumptively compromised and engage IR.

2\. Any viptela-reserved- service account against the authentication servlet in the same log line — presumptive successful bypass; escalate immediately.

3\. Any administrative or service account created or modified on the manager without a corresponding change record during the hunt window.

4\. Any YARA hit from SDWAN\_AuthBypass\_Log\_Artifacts against a copy of /var/log/nms on an affected manager.

5\. Any YARA hit from Credential\_Dump\_Tool\_Memory\_Artifacts against the process memory of a host reachable from the manager.

6\. Any Snort/Suricata Rule 2 alert (encoded servlet request accepted), from any source including allowlisted scanners.

7\. Any accepted connection from the manager management IP to an internal host on a remote-service port (SSH, RPC, SMB, RDP, WinRM) not explained by a documented integration, or any outbound connection from the manager to a non-RFC1918 destination.

8\. Any two-engine-confirmed, owned, in-range SD-WAN Manager instance exposed to the internet whose exposure spans the September 2026 exploitation window.

9\. Any configuration or device-template push to OT-serving edge sites that does not map to an approved change record.

10\. Any interactive or network logon on an internal or OT host whose source address is the manager's management IP and that no documented integration explains (the appliance used as a credential source).

#### Hunt Completion Criteria and Reporting

The hunt is complete when: the external-exposure sweep (Hypothesis 1) has run against the full owned public IP inventory with per-hit provenance recorded and every in-range exposed instance either remediated or fed into the internal hypotheses and hunted exhaustively; the Datadog control query has returned rows (proving the servlet path is parsed) and the manager's service-proxy access log and vmanage-server log have been reviewed across the full window for encoded-servlet requests and reserved-account activity; account and configuration-change records on the manager have been reconciled against the change calendar; and the surrounding-fleet CQL and host-memory YARA legs have completed on all reachable hosts. Report one verdict per hypothesis, using its Verdict criteria. A finding in a secondary leg does not downgrade the primary verdict, and a gap in our own collection is a coverage gap, never a Positive. A negative from any leg whose control returned 0 or was not run (no forwarded appliance syslog, an unparsed path attribute, an IDS sensor without decrypted traffic, the window before the data floor) is reported as "Non-Conclusive — \<observation\>; missing \<input\> prevents determining \<question\>", never as clean. Make absence claims only from a single-predicate filter (filter for the indicator and count it), never by reading a distribution table. Quote only query results whose status reads Done. Record every limitation with its direction (for example, "IDS sees management URIs only where TLS is terminated, and inbound only").

The report must contain: the inventory of SD-WAN Manager instances (version, train, patch status against the fixed releases 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1 / Cloud 20.15.605) and internet-exposure status with per-instance provenance; every encoded-servlet or reserved-account hit with timestamp, source IP, and disposition; the reconciliation of account and configuration changes; all YARA and signature hits with disposition; and the EASM sweep's coverage (which owned ranges were and were not searched) with a recommendation to operate the external-exposure sweep as a recurring control. Any confirmed exploitation triggers the incident-response process, administrative-credential and API-token rotation, and a review of managed edge-device configurations for tampering before normal operations resume.

#### Advisory IoC Reference

| IOC Type | IOC |
| --- | --- |
| CVE | CVE-2026-76504 \| CVSS v3.1 9.8 \| Cisco Catalyst SD-WAN Manager (all releases prior to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1 / Cloud 20.15.605) \| Unauthenticated API authentication bypass via improper URI-encoding handling (CWE-177); actively exploited since Sept 2026, CISA KEV. |
| Threat Actor | Unattributed — no named group published by Cisco PSIRT as of this advisory; KEV listing confirms exploitation, not attribution. |
| Malware | None named in source material. |
| Network IOC | Behavioral: HTTP(S) request whose login-servlet path contains a percent-encoding, e.g. POST /%6a\_security\_check (note: the encoded line does not contain the literal j\_security\_check). |
| Network IOC | Behavioral: encoded security\_check request that is serviced rather than met with a 401/403 rejection. |
| Network IOC | Behavioral: outbound connection from the SD-WAN Manager management IP to a non-RFC1918 destination. |
| File IOC | Log artifact: encoded security\_check entries in /var/log/nms/containers/service-proxy/serviceproxy-access.log. |
| File IOC | Log artifact: viptela-reserved- service-account references on the same line as the authentication servlet in /var/log/nms/vmanage-server.log. |
| Behavioral | viptela-reserved- service account against the authentication servlet. |
| Behavioral | Administrative/service account created or modified on the manager with no corresponding change record. |
| Behavioral | Accepted connection from the manager management IP to an internal host on SSH/RPC/SMB/RDP/WinRM. |
| Behavioral | Configuration or device-template push outside the approved change window, especially to OT-serving edge sites. |
| Behavioral | vManage/SD-WAN Manager login interface exposed on an owned public IP (Shodan/Censys/Netlas) with an in-range version banner spanning the Sept 2026 window. |
| Behavioral | Interactive or network logon on an internal/OT host whose source address is the SD-WAN Manager's management IP (appliance as credential source). |

[View full post](https://1898advisories.burnsmcd.com/threat-hunt-plan-cisco-catalyst-sd-wan-manager-api-authentication-bypass-hunting-exploitation-of-an-actively-exploited-zero-day)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The 1898 & Co. Team"
  },
  "dateModified" : "2026-10-08T14:49:18.915Z",
  "datePublished" : "2026-10-08T14:49:18Z",
  "headline" : "Threat Hunt Plan: Cisco Catalyst SD-WAN Manager API Authentication Bypass — Hunting Exploitation of an Actively-Exploited Zero-Day",
  "image" : {
    "@type" : "ImageObject",
    "height" : 60,
    "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
    "width" : 60
  },
  "mainEntityOfPage" : "https://1898advisories.burnsmcd.com/threat-hunt-plan-cisco-catalyst-sd-wan-manager-api-authentication-bypass-hunting-exploitation-of-an-actively-exploited-zero-day",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Advisories | 1898 & Co."
  }
}
```