Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No Workaround
Security / news
Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No Workaround
Cisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.

An unauthenticated attacker with network access to a Cisco Catalyst SD-WAN Manager can call its API as the admin user by sending one request with a URL-encoded character in the login path. Cisco rates CVE-2026-76504 at 9.8 on CVSS 3.1, confirms exploitation, and lists no workaround.

Cisco's security advisory attributes the bug to improper handling of URI encoding, which lets a request skip the authentication rule guarding an endpoint. Horizon3 describes the trigger as /%6a_security_check in place of the legitimate j_security_check path. Horizon3's write-up says the resulting session lands on the netadmin role by default and exposes fabric configuration and policy control.
What an attacker needs
Only reachability. The flaw applies to all configurations, according to The Hacker News, so internet-facing managers carry the most risk and managers behind a restricted management network carry less. Cisco says there is no workaround. A temporary Live Protect shield exists, but the advisory still requires an upgrade.
Cisco-hosted cloud deployments received patch 20.15.605 automatically. Earlier release trains than 20.9 have to migrate to a fixed one.
| Release train | First fixed release |
|---|---|
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Timeline from September to October 3
- September 2026: Cisco PSIRT identifies active exploitation during a Technical Assistance Center support case (The Hacker News).
- September 30: Cisco publishes the advisory and CISA adds the CVE to its Known Exploited Vulnerabilities catalog; Horizon3 ships a NodeZero test the same day.
- October 3: CISA's remediation deadline for federal agencies, per Rapid7.
Cisco, Horizon3, Rapid7 and The Hacker News do not give a count of compromised managers or name the attackers. The advisory confirms only that exploitation happened.
The score fits, but the count of prior flaws does not
The 9.8 is defensible: network vector, no credentials, administrative result. The preconditions that usually soften a score are absent here.
The history is less settled. Rapid7 calls this the third critical authentication bypass in Cisco's SD-WAN control components in 2026, after CVE-2026-20127 and CVE-2026-20182. The Hacker News instead says it is one of eight Cisco SD-WAN vulnerabilities CISA has flagged as exploited in 2026, following CVE-2026-20182, CVE-2026-20245 and CVE-2026-20262. Those counts measure different things, and neither source fully reconciles the other's list.
What to check before upgrading
Cisco asks operators to search /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for j_security_check requests from unknown addresses, and for accounts whose names begin viptela-reserved-. Run request admin-tech before upgrading to preserve evidence, then open a Severity 3 case with Cisco TAC.
If a manager cannot be upgraded today, restrict ports 443, 22 and 830 to jump hosts or management subnets. Other edge appliances under exploitation in October 2026 include Citrix NetScaler's SAML flaw and FortiMail's unpatched file-write bug.
Sources
More in Security
- 01NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload DownloadCitrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.
- 02Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 03Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the PatchCVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.
- 04FortiMail CVE-2026-104286 Is Exploited With No Fixed Release, and the Workaround Is Turning Off a FeatureAn unauthenticated path-traversal bug scoring 9.8 lets an attacker write files to FortiMail 7.2 through 8.0. CISA's deadline is October 4; Fortinet had no patch when the advisory went out.