Cisco SD-WAN Manager Flaw Hands Unauthenticated Callers the Admin API
Security / news
Cisco SD-WAN Manager Flaw Hands Unauthenticated Callers the Admin API
Cisco confirmed exploitation of CVE-2026-76504, rated 9.8, in the advisory it published Sept. 30 with fixed releases for six software trains and no workaround.

An unauthenticated remote attacker who can reach Cisco Catalyst SD-WAN Manager can call its API as the admin user, and Cisco says attackers are already doing it. The flaw, CVE-2026-76504, is rated 9.8 out of 10 on the CVSS severity scale, and Cisco lists no workaround, so the fix is an upgrade.
Cisco published its advisory on Sept. 30, 2026. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog the same day, listing it as a "Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability."
What an attacker needs for CVE-2026-76504
The attacker needs network reach to the Manager's web interface and nothing else. Cisco says the product is affected in all configurations, and it attributes the bug to "improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule."
In plain terms, a request path written with percent-encoded characters slips past a check that matches the plain spelling. Rapid7 gives the pattern to look for as POST /%6a_security_check, where %6a is the hex encoding of the letter j in j_security_check, the login endpoint.
Fixed releases by software train
Restrict internet access to the Manager and firewall it until you can upgrade. Cisco's fixed releases:
| Software train | Fixed release |
|---|---|
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Rapid7 tells organisations to upgrade "on an emergency basis, outside of normal patch cycles." Cisco lists the cloud version 20.15.605 as auto-remediated.
The score fits, but it leaves out exploitation
The score matches what Cisco describes: remote, unauthenticated, administrator-level result. What a CVSS number cannot carry is that Cisco confirms exploitation as of September 2026.
Neither the advisory nor the CISA alert says how many systems were compromised, who is behind the activity, or what the attackers did with admin access. Nothing published yet allows a defender to bound the damage, so the safe assumption on an exposed Manager is that the API was reachable by anyone.
CISA's catalog has carried other management-plane products before, among them the Cisco, Citrix and Fortinet entries and an Artifactory chain that ended in admin access. This one shares the shape: a management interface that an attacker can reach without credentials.
How to check an exposed Manager
Cisco's detection guidance points to two things in the logs: URI-encoded requests to the j_security_check endpoint, and authentication attempts involving service accounts whose names begin "viptela-reserved-". Rapid7 says to search /var/log/nms/containers/service-proxy/serviceproxy-access.log for encoded requests.

Because the bypass yields the admin identity, an attacker's requests may look like ordinary administrator traffic after the first encoded one, so search from that first request onward. Cloud customers have the least to do: Cisco lists version 20.15.605 as remediated automatically.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.