CVE-2026-76504 lets an unauthenticated attacker URL-encode one character to slip past Cisco SD-WAN Manager API login as admin. Exploited; no workaround.
Cisco has disclosed an actively exploited authentication bypass in Catalyst SD-WAN Manager (formerly vManage) that hands an unauthenticated attacker on the network the API privileges of the admin user. The trick is small: URL-encode a single character of a protected path, and a rule meant to guard that path stops matching it.
The flaw is tracked as CVE-2026-76504 and scores CVSS 9.8 (Critical). Cisco published its advisory on 30 September 2026 and said its PSIRT became aware of active exploitation that month. CISA added it to the Known Exploited Vulnerabilities catalog the same day, under the name "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability", and gave federal agencies until 3 October to act. Three days is a short window, even by KEV standards.
There is no workaround. Upgrading is the fix.
What is broken
According to Cisco, the bug sits in the API's session-based authentication management. SD-WAN Manager applies an authentication rule meant to restrict access to a specific API endpoint, but it mishandles URI encoding in the incoming HTTP request. A request that encodes part of the path does not match the rule, slips past it, and lands on the API with admin rights. NVD and Cisco classify it as CWE-177, improper handling of URL encoding (hex encoding).
The advisory's own indicator of compromise shows what that looks like on the wire:
POST /%6a_security_check HTTP/1.1
%6a is the URL-encoded form of the letter j, so the server ends up treating the request as one for j_security_check even though the rule never saw that string. Cisco adds a warning that matters for detection: that is "only an example", and any one character in the request can be encoded to exploit the flaw. A detection rule that looks only for %6a will miss the next variant.
Cisco says the bug was found while its Technical Assistance Center worked a customer support case. It is tracked as Cisco bug CSCww79570.
Who is affected
The advisory covers Cisco Catalyst SD-WAN Manager regardless of device configuration. NVD's configuration data marks every release before 20.9.10.1 as vulnerable, along with the 20.12, 20.15, 20.18 and 26.1 trains below their fixed builds, and 26.2.
| Release train | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Cisco-hosted customers are in a different position. For Catalyst SD-WAN Cloud Hosted environments, Cisco says the mitigation is already deployed, and it lists Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605 as the fixed cloud version. On-premises and self-managed deployments need the upgrade.
The third SD-WAN bypass this year
This is a different bug from the one we covered in May. CVE-2026-20182 was a CVSS 10.0 flaw in the vdaemon control-plane peering service, disclosed and added to KEV on 14 May and exploited by the actor Cisco Talos tracks as UAT-8616. It followed CVE-2026-20127, another CVSS 10.0 peering-authentication bypass published and added to KEV on 25 February. CVE-2026-76504 is in the Manager's web API, not the peering handshake. Rapid7 counts it as the third critical authentication bypass in Catalyst SD-WAN components in 2026.
Cisco has not attributed the new exploitation to any actor, and the advisory does not say how widespread it is. Both CISA and Cisco list ransomware use as unknown.
Three Catalyst SD-WAN authentication bypasses in 2026, each added to CISA KEV on its disclosure day. Sources: NVD, CISA KEV, Cisco.
What defenders should do
- Upgrade to the first fixed release for your train, or migrate if you run anything older than 20.9. Cisco offers no configuration workaround.
- Take the Manager off the internet until it is patched. Cisco's only interim advice is to put the system behind a filtering device such as a firewall and allow only known, trusted hosts on the ports and protocols in its user guides.
- Hunt for exploitation already done. Cisco names two logs:
/var/log/nms/containers/service-proxy/serviceproxy-access.log: look forj_security_checkrequests with an encoded character in the path, from sources you do not recognise./var/log/nms/vmanage-server.log: look for sessions with usernames startingviptela-reserved-.
- Treat a hit as a full compromise of the SD-WAN control plane. Admin API access on the Manager reaches the configuration it pushes to every edge router, so review recent configuration changes, users and API tokens, not just the logs above.
- Write detections for any encoded character, not the single
%6aexample in the advisory.
Federal civilian agencies fall under CISA's 3 October deadline. Everyone else running an exposed, self-hosted SD-WAN Manager is facing the same exploitation.