Dev News Daily ENDE

Cisco SD-WAN Manager bug CVE-2026-76504: one encoded character skips login

Cisco published an advisory on 30 September for CVE-2026-76504, a critical authentication bypass in the API of Cisco Catalyst SD-WAN Manager, according to a write-up by Rapid7. Rated 9.8 under CVSS 3.1, the bug is a URL-encoding mistake (CWE-177): a single specially built HTTP request, sent without any credentials, gets past the authentication check on one API endpoint and is treated as coming from the admin user.

Cisco says attackers are already using it; its incident response team learned of the attacks in September. Any installation reachable from the internet is exposed, whatever its configuration. There is no workaround. Fixed software releases are available, and Rapid7 recommends upgrading on an emergency basis, outside the normal patch cycle. The cloud-based Cisco SD-WAN Cloud (Cisco Managed) service is fixed in release 20.15.605, and Cisco says no customer action is needed there.

As a temporary measure for on-premises systems, Cisco recommends blocking access from unsecured networks or limiting it to known hosts behind a filtering device, while still applying the update.

Because exploitation has occurred, administrators are advised to check for compromise. Cisco points to two logs. In /var/log/nms/containers/service-proxy/serviceproxy-access.log, look for requests to the j_security_check path containing an encoded character, such as POST /%6a_security_check; Cisco says any single character can be encoded, so %6a is only an example. In /var/log/nms/vmanage-server.log, look for j_security_check requests with usernames beginning viptela-reserved-. Such entries can also appear in normal operation and need to be judged against the expected traffic.

Cisco SD-WAN Manager bug CVE-2026-76504: one encoded character skips login
Cisco SD-WAN Manager bug CVE-2026-76504: one encoded character skips login — Dev News Daily

Why it matters

This is the third critical unauthenticated flaw in internet-facing Catalyst SD-WAN control components this year, after CVE-2026-20127 and CVE-2026-20182, though in a different code path. An SD-WAN manager controls the network it sits on, so an admin-level API bypass is a direct route to that network.

Written by Victoria Shinder.