critical Cve 2026 76504 · Exploits

Cisco SD-WAN Manager Zero-Day CVE-2026-76504: One Encoded Character Unlocks the Admin API

Data graphic: A critical-rated Cisco Catalyst SD-WAN Manager zero-day, CVE-2026-76504 CVSS 9.8 , shown as an attack path. A crafted request to POST /%6a_security_check, where %6a decodes to j, never matches the authentication rule and gets unauthenticated admin API access. CISA added it to KEV on 30 Sep with a 3 Oct deadline, and there is no workaround.
SH

Vulnerability analyst · Updated Oct 2, 2026, 8:05 AM EDT

CVE-2026-76504 lets an unauthenticated attacker URL-encode one character to slip past Cisco SD-WAN Manager API login as admin. Exploited; no workaround.

Cisco has disclosed an actively exploited authentication bypass in Catalyst SD-WAN Manager (formerly vManage) that hands an unauthenticated attacker on the network the API privileges of the admin user. The trick is small: URL-encode a single character of a protected path, and a rule meant to guard that path stops matching it.

The flaw is tracked as CVE-2026-76504 and scores CVSS 9.8 (Critical). Cisco published its advisory on 30 September 2026 and said its PSIRT became aware of active exploitation that month. CISA added it to the Known Exploited Vulnerabilities catalog the same day, under the name "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability", and gave federal agencies until 3 October to act. Three days is a short window, even by KEV standards.

There is no workaround. Upgrading is the fix.

What is broken

According to Cisco, the bug sits in the API's session-based authentication management. SD-WAN Manager applies an authentication rule meant to restrict access to a specific API endpoint, but it mishandles URI encoding in the incoming HTTP request. A request that encodes part of the path does not match the rule, slips past it, and lands on the API with admin rights. NVD and Cisco classify it as CWE-177, improper handling of URL encoding (hex encoding).

The advisory's own indicator of compromise shows what that looks like on the wire:

POST /%6a_security_check HTTP/1.1

%6a is the URL-encoded form of the letter j, so the server ends up treating the request as one for j_security_check even though the rule never saw that string. Cisco adds a warning that matters for detection: that is "only an example", and any one character in the request can be encoded to exploit the flaw. A detection rule that looks only for %6a will miss the next variant.

Cisco says the bug was found while its Technical Assistance Center worked a customer support case. It is tracked as Cisco bug CSCww79570.

Who is affected

The advisory covers Cisco Catalyst SD-WAN Manager regardless of device configuration. NVD's configuration data marks every release before 20.9.10.1 as vulnerable, along with the 20.12, 20.15, 20.18 and 26.1 trains below their fixed builds, and 26.2.

Release trainFirst fixed release
Earlier than 20.9Migrate to a fixed release
20.920.9.10.1
20.1220.12.8.2
20.1520.15.6.1
20.1820.18.4.1
26.126.1.2.1
26.226.2.1

Cisco-hosted customers are in a different position. For Catalyst SD-WAN Cloud Hosted environments, Cisco says the mitigation is already deployed, and it lists Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605 as the fixed cloud version. On-premises and self-managed deployments need the upgrade.

The third SD-WAN bypass this year

This is a different bug from the one we covered in May. CVE-2026-20182 was a CVSS 10.0 flaw in the vdaemon control-plane peering service, disclosed and added to KEV on 14 May and exploited by the actor Cisco Talos tracks as UAT-8616. It followed CVE-2026-20127, another CVSS 10.0 peering-authentication bypass published and added to KEV on 25 February. CVE-2026-76504 is in the Manager's web API, not the peering handshake. Rapid7 counts it as the third critical authentication bypass in Catalyst SD-WAN components in 2026.

Cisco has not attributed the new exploitation to any actor, and the advisory does not say how widespread it is. Both CISA and Cisco list ransomware use as unknown.

Data graphic: a timeline of the three Cisco Catalyst SD-WAN authentication bypasses of 2026. CVE-2026-20127 CVSS 10.0, 25 Feb , CVE-2026-20182 CVSS 10.0, 14 May, 78 days later and CVE-2026-76504 CVSS 9.8, 30 Sep, 139 days after that , each added to CISA KEV the day Cisco disclosed it. A zoomed panel shows the 3 days from the latest one's KEV listing to its 3 Oct federal due date, and there is no workaround.

Three Catalyst SD-WAN authentication bypasses in 2026, each added to CISA KEV on its disclosure day. Sources: NVD, CISA KEV, Cisco.

What defenders should do

  1. Upgrade to the first fixed release for your train, or migrate if you run anything older than 20.9. Cisco offers no configuration workaround.
  2. Take the Manager off the internet until it is patched. Cisco's only interim advice is to put the system behind a filtering device such as a firewall and allow only known, trusted hosts on the ports and protocols in its user guides.
  3. Hunt for exploitation already done. Cisco names two logs:
    • /var/log/nms/containers/service-proxy/serviceproxy-access.log: look for j_security_check requests with an encoded character in the path, from sources you do not recognise.
    • /var/log/nms/vmanage-server.log: look for sessions with usernames starting viptela-reserved-.
  4. Treat a hit as a full compromise of the SD-WAN control plane. Admin API access on the Manager reaches the configuration it pushes to every edge router, so review recent configuration changes, users and API tokens, not just the logs above.
  5. Write detections for any encoded character, not the single %6a example in the advisory.

Federal civilian agencies fall under CISA's 3 October deadline. Everyone else running an exposed, self-hosted SD-WAN Manager is facing the same exploitation.

Sources

Keep reading

All latest →
  1. highExploitsWordPress Core Flaw CVE-2026-87902 Drew Exploit Attempts on Patch Day7 min
  2. criticalExploitsCheck Point Management Servers Were a Zero-Day for Two Months Before the Fix6 min
  3. criticalExploitsExploited FortiMail Flaw Has No Patch Yet: Disable IBE Now5 min
  4. criticalExploitsCitrix NetScaler Zero-Days Planted Webshells Weeks Before the Patch8 min
  5. criticalExploitsUnder Active Attack: Cisco ISE Zero-Day (CVE-2026-76460) Grants Remote Unauthenticated Admin Access8 min
  6. criticalExploitsShieldCrash Zero-Day Analysis: Bypassing Microsoft Defender's ShieldBreak Fix (CVE-2026-69414) for Arbitrary SYSTEM File Reads7 min