One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access
A crafted HTTP request can give attackers administrator-level API access to Cisco Catalyst SD-WAN Manager without a login. Cisco says the flaw is already being exploited.
Cisco disclosed CVE-2026-76504 on 30 September and gave it a critical CVSS score of 9.8. The company says an unauthenticated remote attacker can abuse improper URI encoding to bypass an authentication rule and reach the Catalyst SD-WAN Manager API with the privileges of the admin user.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue only hours later. This is not a theoretical patch-cycle item. It is a management-plane exposure with confirmed exploitation and a three-day federal remediation window.
One encoded character can defeat the authentication rule
The vulnerable logic is meant to restrict access to a particular API endpoint. Cisco says encoding a character in the request URI can let a crafted request slip past that rule.
Cisco’s example uses %6a in place of the letter j in j_security_check, but that is only an illustration. The advisory warns that an attacker can encode any one character in the request to trigger the vulnerable behaviour. Detection that looks only for /%6a_security_check will therefore be too narrow.
The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration. Actual remote reachability still matters. Cisco specifically warns that systems with ports exposed to the internet are at risk, and recommends preventing access from unsecured networks.
Administrator API access is not the same as root
A successful attack provides administrator-level access to the SD-WAN Manager API. That gives an intruder a privileged route into the platform that controls the overlay, but Cisco’s advisory does not say this flaw automatically provides host root, compromises every managed edge device or proves that configurations were changed.
Those distinctions matter during incident response. Teams should treat unauthorised API access as a potential control-plane compromise, then establish what the account did, which objects or policies it touched and whether any resulting change reached managed infrastructure.
BlackTree’s earlier report, The SD-WAN Control Plane Was Exploited. Cisco Said Preserve Evidence Before Patching., covered a different cluster of exploited SD-WAN vulnerabilities. The new authentication bypass is separate, but it reinforces the same operational lesson: once the management plane is suspect, patching alone cannot prove that the network state is trustworthy.
Six release trains have fixes
Cisco says there is no workaround. The permanent action is to install a fixed release:
| On-premises release train | First fixed release or action |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Cisco-managed SD-WAN Cloud is a separate case. Cisco says it fixed the issue in cloud release 20.15.605 and that customers do not need to perform a software update. They can check remediation status or the current version through the service GUI.
For on-premises deployments that cannot be upgraded immediately, Cisco recommends restricting management access to known, trusted hosts and placing SD-WAN control components behind filtering devices such as firewalls. Cisco explicitly describes this as a mitigation, not a workaround, and says customers should test it for operational impact before deployment.
Hunt in both Manager logs
Cisco published concrete forensic checks for two log files.
First, inspect /var/log/nms/containers/service-proxy/serviceproxy-access.log for calls to j_security_check from unknown or unauthorised IP addresses. Look for encoded characters anywhere in the relevant request, not just %6a.
Second, inspect /var/log/nms/vmanage-server.log for related j_security_check activity from unknown or unauthorised addresses, especially requests associated with user names beginning viptela-reserved-.
These patterns are leads, not verdicts. Cisco warns that some of the listed indicators can occur during normal operations. Analysts need to compare them with the environment’s normal network posture, administrative activity and source-address history before declaring a compromise.
Preserve evidence before making broad changes where operationally safe. CISA’s forensic triage guidance explains why collecting relevant artefacts before patching matters. Cisco advises customers that need help assessing compromise to run request admin-tech, retain the resulting file and open a Cisco TAC case at Severity 3 with CVE-2026-76504 in the case title.
Who must meet the 3 October deadline
CISA’s catalogue lists 3 October 2026 as the remediation due date and marks forensic triage as required. Under Binding Operational Directive 26-04, that compulsory deadline applies to in-scope US Federal Civilian Executive Branch systems. It is not a universal legal deadline for every organisation running Cisco SD-WAN.
Everyone else should still treat the date as a strong risk signal. Cisco has confirmed active exploitation, the attack is remote and unauthenticated, and the affected system controls a consequential part of the network. Organisations should identify exposed Managers, reduce reachability, preserve evidence, inspect both logs and move to the appropriate fixed release.
Cisco has not identified the attacker, named victims or described the scale or objective of the activity. What it has confirmed is enough to act: a crafted encoded request can cross the authentication boundary of a critical management system, and someone is already using it.
Sources
- Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability, first published 30 September 2026 at 13:00 GMT, or 15:00 CEST.
- CISA Known Exploited Vulnerabilities catalogue, catalogue version 2026.09.30 released 30 September 2026 at 16:59:23 UTC, or 18:59:23 CEST.
- CISA Binding Operational Directive 26-04, published 10 June 2026. CISA provides a date but no publication time.
- CISA forensic triage implementation guidance, updated 25 August 2026.


