Skip to content

Security3 publishers2 min readPublished

Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.

The Watch · Security desk

Illustration accompanying Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

What happened

  • Cisco's product security team learned of the exploitation during September, and the advisory with fixed releases followed on September 30.
  • Cisco lists no workaround; its interim step is to block access from unsecured networks or limit it to known hosts behind a filtering device, then patch anyway.
  • Signs of exploitation are encoded j_security_check requests in the service-proxy access log and viptela-reserved- usernames in vmanage-server.log.
  • BleepingComputer counts CVE-2026-76504 as the fifth Catalyst SD-WAN zero-day exploited in the wild since the start of 2026.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision An internet-exposed on-premises Manager needs an out-of-cycle upgrade and a compromise review, because attackers had the bug before the fix shipped.
  • exposure A successful request lands admin API rights on the console that manages up to 6,000 SD-WAN devices, so one Manager puts the whole fabric it runs within reach.
  • contradiction Hunts keyed to the %6a string in BleepingComputer's report will miss requests that encode other characters, and Cisco says any single character works.
  • precedent Separate code paths in the same internet-facing component have failed this year, so keeping the Manager off open networks also limits exposure to the next bypass.

The fault is in the API's session-based authentication management [16]. "This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint," Cisco said [15]. No login is required. A crafted request from any network that can reach the Manager gets API access with the admin user's privileges [2]. The Manager, formerly vManage, is the dashboard that monitors and manages up to 6,000 SD-WAN devices [14].

Hunting needs care. BleepingComputer reported that threat actors are using %6a, the encoded letter j, in malicious requests [13]. Cisco's guidance, as Rapid7 relays it, treats %6a as one example and says encoding any single character in the request works [12]. A search for the literal string catches one variant. Cisco also says matching log entries can appear during standard operations and should be judged against normal network posture [12].

Rapid7 recommends upgrading on an emergency basis, outside normal patch cycles, and auditing affected systems for compromise because exploitation has already happened [5]. Cisco customers can open a Severity 3 TAC case with CVE-2026-76504 in the title and attach an admin-tech file produced by the request admin-tech command [9]. Rapid7 expected its own scanner checks in its October 1 content release [10].

Deployment type sets the workload. Cisco fixed its Cisco-managed SD-WAN Cloud service in release 20.15.605 and says those customers need take no action [7]. Cloud Hosted environments already sit behind the access filtering, and Cisco still says to apply updates where that filtering is in place [8]. Internet-exposed ports are what put a Manager at risk of compromise [17].

In early June, attackers used CVE-2026-20245 and CVE-2026-20262 to gain root on vulnerable SD-WAN systems [19]. Rapid7 also lists CVE-2026-20127 and CVE-2026-20182, unauthenticated peering flaws in the vdaemon service earlier this year, and notes that CVE-2026-76504 sits on a separate API authentication path [6]. In Rapid7's view, the recurrence of authentication bypasses in internet-facing Catalyst SD-WAN control components argues for emergency remediation [6]. Cisco did not share details of the attacks, so the public record does not show whether one group is behind this year's exploitation [18]. CISA has tagged 90 Cisco vulnerabilities as exploited since November 2021, four of them in Catalyst SD-WAN Manager and seven used by ransomware operations [20].

What to watch

  • Whether Cisco or other responders publish who is exploiting CVE-2026-76504 and how many Managers were hit.
  • Whether CISA adds CVE-2026-76504 to its catalog of exploited vulnerabilities.
  • Whether new Cisco indicators reach beyond j_security_check requests or link this activity to the June CVE-2026-20245 and CVE-2026-20262 attacks.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories