Cisco SD-WAN Manager Zero-Day CVE-2026-76504 Has No Workaround
Security / news
Cisco SD-WAN Manager Zero-Day CVE-2026-76504 Has No Workaround
A single percent-encoded letter in a login path bypasses authentication on every deployment, and Cisco's fix list starts at release 20.9.10.1.

An unauthenticated attacker can send one crafted HTTP request to Cisco Catalyst SD-WAN Manager and get admin-level access to its API, and Cisco says that has been happening since September. The flaw, CVE-2026-76504, is rated 9.8 out of 10 on the CVSS severity scale. Cisco lists no workaround.
Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU on Sept. 30, 2026. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day with an Oct. 3 deadline for federal civilian agencies, according to Rapid7.
The vector, and what it needs
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: network-reachable, low complexity, no privileges, no user interaction. The weakness is CWE-177, improper handling of URL encoding. Cisco says the bug lets an attacker bypass an authentication rule and reach the API with administrator privileges.
The score does not overstate this one. The advisory says all Catalyst SD-WAN Manager deployments are affected regardless of configuration, so there is no unusual setting to rule yourself out with. The practical precondition is network reachability of the Manager's web interface.
Cisco found the problem while resolving a Technical Assistance Center support case. Its advisory says: "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability." It does not say how many customers were hit or who is behind it.
What to look for in the logs
The indicators are specific. The login path on these systems is j_security_check, and the attack replaces a letter with its percent-encoded form. BleepingComputer reports that attackers use %6a for the letter j. Rapid7 gives the example POST /%6a_security_check and says Cisco warns that an attacker can encode any single character, so a search for that one string will miss variants.
Two files are worth searching. In serviceproxy-access.log, under /var/log/nms/containers/service-proxy, look for requests to the login path from addresses you do not know. In /var/log/nms/vmanage-server.log, look for usernames that begin with viptela-reserved-. Cisco says these entries can also appear in normal operation, so compare them against a baseline before declaring a compromise. Cisco also links Snort Rule 67179 and recommends opening a TAC case for a compromise assessment.
Fixed releases
| Release train | Fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Cisco-managed SD-WAN Cloud was fixed in 20.15.605, and customers there need to do nothing. Cisco also shipped a Live Protect shield for partial protection while a fix is scheduled, and warns it may block legitimate users who rely on URI encoding when they log in. Cisco says upgrading is the only full remediation. Without one, Cisco recommends keeping the Manager off untrusted networks and behind a filtering device.
Fifth SD-WAN zero-day in 2026
BleepingComputer counts this as the fifth exploited SD-WAN zero-day of 2026, after CVE-2026-20127 in February, CVE-2026-20182 in May, and CVE-2026-20245 and CVE-2026-20262 in early June. Rapid7 notes the earlier two Manager bugs sat in the vdaemon peering service, so this is a different code path, not a bypass of an earlier fix.
- February to May2 CVEs
- Early June2 CVEs
- Sept. 301 CVEs
Source: BleepingComputer, Sept. 30, 2026 (accessed 2026-10-08)
BleepingComputer adds that CISA has listed 90 Cisco vulnerabilities as exploited since November 2021, four of them in SD-WAN Manager and seven used by ransomware operators. For the pattern of flaws that survive on edge devices after disclosure, see The Terminal's coverage of the Cling botnet and the Apple CoreGraphics zero-day.
The next number to check is your own Manager's release string: anything below 20.9.10.1 on the 20.9 train is exposed today.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 04Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.