- What: Cisco disclosed on September 30 that attackers are exploiting CVE-2026-76504, a URI-encoding flaw in Catalyst SD-WAN Manager that bypasses API authentication.
- Impact: An unauthenticated attacker who can reach the Manager API can act as the admin user, whose default netadmin role can perform every operation on the device and the SD-WAN fabric it controls.
- Fix / mitigation: Cisco has fixed releases including 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, with no workaround, and advises restricting Manager access to trusted hosts until upgraded.
- Who's at risk: Any organization running on-prem Cisco Catalyst SD-WAN Manager in any configuration, especially instances reachable from the internet, including those already patched for the May and June SD-WAN flaws.
Cisco confirmed on September 30 that attackers are actively exploiting a critical zero-day in Catalyst SD-WAN Manager, the controller organizations use to run their entire Cisco SD-WAN fabric. The flaw, CVE-2026-76504, scores 9.8 on CVSS and lets a remote attacker with no credentials use the Manager API as the admin user. Fixed releases are available. There is no workaround. Any Manager exposed to the internet is at risk of compromise, according to Cisco.
This is the fourth SD-WAN Manager flaw Cisco has patched since May, and it is not covered by the earlier fixes. A Manager last upgraded for the May or June advisories still needs this update.
How the Bypass Works
The bug sits in the part of the Manager API that handles login sessions. The Manager mishandles URI encoding in HTTP requests. A crafted request that encodes part of the path can slip past an authentication rule meant to restrict access to a single API endpoint. The attacker needs only network reachability to the Manager API: no account, no stolen session, no user interaction.
The payoff is significant. By default the admin user holds the netadmin role, which Cisco describes as allowed to perform all operations on the device. SD-WAN Manager pushes configuration and policy to every edge router in the fabric, so admin API access on the controller is effectively administrative reach across the WAN it manages.
The flaw affects SD-WAN Manager regardless of configuration. Cisco lists no other product as affected.
Cisco's PSIRT became aware of active exploitation in September 2026 after the flaw surfaced during a TAC support case. The advisory does not say how many customers were hit, when attacks began, who is behind them, or what attackers did once inside. It also does not say whether upgrading removes an attacker who already has access.
Fixed Releases
Cisco lists these as the first fixed releases for each release train:
- Earlier than 20.9: migrate to a fixed release
- 20.9: 20.9.10.1
- 20.12: 20.12.8.2
- 20.15: 20.15.6.1
- 20.18: 20.18.4.1
- 26.1: 26.1.2.1
- 26.2: 26.2.1
Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and those customers need to take no action. Cisco Catalyst SD-WAN Cloud Hosted environments already have the network access mitigation in place.
Gaps in the Advisory
Several omissions matter for anyone scoping exposure. The table does not list the 20.10, 20.11, 20.13, 20.14 or 20.16 release trains, all of which appeared in Cisco's May advisory. The advisory also does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP), two deployment types that were named in the May and June advisories. Organizations on those trains or deployment types should not read their absence as confirmation they are unaffected; the advisory is silent on them.
CVE-2026-76504 is separate from CVE-2026-20182, fixed in May, and CVE-2026-20245 and CVE-2026-20262, fixed in June. The fixed releases for those three flaws are all older than the ones listed for this bug, so earlier patching does not close it.
Vendor Mitigation Until Upgrade
For on-prem Managers that cannot be upgraded immediately, Cisco advises restricting access from unsecured networks such as the internet. Where internet access is required, Cisco says only known, trusted hosts should be allowed in and control components should sit behind a firewall. Cisco reports the mitigation worked in a test environment and advises customers to assess its impact on their own networks before relying on it.
This aligns with Cisco's existing SD-WAN hardening guide, which states that administrative interfaces such as ports 443, 22 and 830 should not be exposed directly to the internet, and that HTTPS access to the Manager should come only from a jump host or management subnet. Managers that followed that guidance had a much smaller attack surface for this bug.
Indicators Cisco Has Published
Cisco's indicators center on j_security_check, the request path the Manager uses for session-based logins. In Cisco's example, one character of the path is URI-encoded, producing /%6a_security_check, where %6a is the letter j. Any single character in the request can be encoded, so %6a is only one variant.
Cisco points to two logs where j_security_check entries from unknown or unauthorized IP addresses are of interest: the service proxy access log under /var/log/nms/containers/service-proxy/, and vmanage-server.log under /var/log/nms/, particularly entries for users whose names begin with viptela-reserved-. Those names belong to reserved system service accounts. Cisco notes that the same entries can appear during normal operation, so matches require review against baseline activity to rule out false positives. The advisory ships no detection rule.
Cisco directs customers who suspect compromise to open a Severity 3 TAC case with CVE-2026-76504 in the title and supply admin-tech output from the Manager. For the May flaw and the first June flaw, Cisco stated an update alone would not resolve a confirmed compromise and told customers to collect admin-tech before upgrading. Upgrading first risks destroying the evidence needed to scope an intrusion.
RedEye Assessment
SD-WAN controllers have become a repeat target in 2026. As of September 30, CISA's Known Exploited Vulnerabilities catalog lists eight Cisco SD-WAN flaws added this year. The pattern is consistent: a management plane that controls hundreds or thousands of branch devices, exposed more often than it should be, with authentication logic that keeps failing under crafted input.
Three points stand out for defenders. First, patch cadence on SD-WAN Manager has to be treated as monthly, not annual: four advisories in five months means any Manager not touched since June is exposed. Second, the missing release trains and deployment types leave real uncertainty that only Cisco can resolve. Third, because Cisco has not said whether upgrading evicts an existing attacker, a clean patch is not proof of a clean controller. Organizations with any internet-reachable Manager during September should assume compromise is possible until log review and TAC analysis say otherwise.
RedEye Security can assess SD-WAN Manager exposure, review Manager logs against Cisco's published indicators, and support incident scoping if suspicious j_security_check activity turns up. Contact our team for an assessment.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us