Attackers Exploit a Hex-Encoding Bypass in Cisco SD-WAN Manager, and CISA Sets an October 3 Deadline
Cisco says attackers are exploiting CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager that a single hex-encoded character can trigger, and CISA has given federal agencies...
Cisco says attackers are exploiting a critical authentication bypass in Catalyst SD-WAN Manager, the management console formerly known as vManage, and that encoding a single character of a login path is enough to trigger it. The flaw, CVE-2026-76504, carries a CVSS 3.1 base score of 9.8, needs no credentials, and lets a remote attacker use the Manager’s API as the admin user, according to Cisco’s advisory published on September 30, 2026. CISA added the bug to its Known Exploited Vulnerabilities catalog the same day and gave federal civilian agencies until Saturday, October 3, to act.
Table Of Content
Cisco’s Product Security Incident Response Team (PSIRT) “became aware of active exploitation of this vulnerability” in September 2026, the advisory says, and the bug was found while Cisco resolved a Technical Assistance Center (TAC) support case. The advisory does not say how many customers were hit, when the attacks began, who is behind them or what the attackers did with the access.
One encoded character is enough
Cisco describes a flaw in the API session-based authentication management of SD-WAN Manager. In its words, the bug “is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint.” An attacker only has to send a crafted HTTP request to the Manager’s API.
The example in Cisco’s indicators of compromise shows the trick. The login path j_security_check, which The Hacker News describes as the path the Manager uses for session-based logins, is requested as /%6a_security_check, where %6a is the URI-encoded letter j. Cisco stresses that the letter is only an example and that the vulnerability “will allow any one character that is encoded in the request to be used to exploit this.”
MITRE files this class of mistake as CWE-177, Improper Handling of URL Encoding (Hex Encoding), and CISA’s catalog names the bug the Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability. The flaw affects the Manager “regardless of system configuration,” Cisco says. The Hacker News adds that the admin user holds the netadmin role by default, which is allowed to perform all operations on the device, and BleepingComputer describes the Manager as software that lets administrators monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
At the time of writing, the National Vulnerability Database entry is still marked Undergoing Analysis. The 9.8 score and its vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, are Cisco’s own, while CISA’s entry in the record rates exploitation as active, the attack as automatable and the technical impact as total.
Which releases fix it
Cisco’s fixed releases are listed below. The company also fixed its cloud-based Cisco SD-WAN Cloud (Cisco Managed) service in release 20.15.605 and says no customer action is needed there.
| Catalyst SD-WAN release | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
There is no workaround. For on-premises systems Cisco lists a mitigation instead: restrict access from unsecured networks such as the internet, allow only known, trusted hosts if internet access is required, and protect the control components behind a filtering device such as a firewall. Cisco says Cloud Hosted environments already have that mitigation in place, and Rapid7 still advises upgrading even where it is applied.
Patching for earlier 2026 flaws does not cover this one. Cisco’s advisory for the May flaw, CVE-2026-20182, lists 20.9.9.1, 20.12.7.1, 20.15.5.2, 20.18.2.2 and 26.1.1.1 as the latest fixed releases in those trains, and each is older than the matching release above. A Manager last upgraded for the May fix still needs this update.
The new table also omits trains that the May advisory covered: 20.10, 20.11, 20.13, 20.14 and 20.16, four of which that advisory footnoted as having reached End of Software Maintenance. It does not mention Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP) either, two deployment types the May advisory named as affected. Owners of those systems should confirm their path with Cisco or move to a listed train.
How to check whether a Manager was hit
Cisco points administrators to two log files. In /var/log/nms/containers/service-proxy/serviceproxy-access.log, look for j_security_check requests from unknown or unauthorized IP addresses, such as this request from Cisco’s example, which was answered with HTTP 200:
POST /%6a_security_check HTTP/1.1
In /var/log/nms/vmanage-server.log, look for j_security_check entries tied to users whose names start with viptela-reserved-, the prefix of the system service accounts Cisco documents in its configuration guide. Cisco’s example reads:
Request Stored in Map is (/%6a_security_check) for user (viptela-reserved-..)
Cisco warns that these entries can also appear during standard operations and must be assessed against normal network posture to avoid false positives. Because any one encoded character works, a search for %6a alone can miss variants. For help determining whether a Manager was compromised, Cisco says customers may open a Severity 3 TAC case with CVE-2026-76504 in the title, and encourages them to run request admin-tech on the Manager first so the file can be reviewed.
The new advisory does not say whether upgrading removes an attacker who is already inside. Cisco’s May advisory was explicit. It told customers to run request admin-tech on each control component before upgrading, to preserve possible indicators of compromise, and warned that on a system confirmed to be compromised “applying the software update alone will not resolve the vulnerability.” Collecting the admin-tech file first is a cheap way to keep the evidence.
Another SD-WAN entry on CISA’s list
Counted from CISA’s JSON feed, the catalog now holds nine Cisco SD-WAN entries, all added in 2026: CVE-2026-20127 and CVE-2022-20775 on February 25, CVE-2026-20122, CVE-2026-20133 and CVE-2026-20128 on April 20, CVE-2026-20182 on May 14, CVE-2026-20245 on June 9, CVE-2026-20262 on June 15, and now CVE-2026-76504. BleepingComputer counts the new bug as the fifth SD-WAN zero-day exploited this year. After the earlier exploitation, CISA issued Emergency Directive 26-03, which requires federal civilian agencies to inventory their Cisco SD-WAN systems, update them and assess compromise, according to CISA’s SD-WAN alert. That alert was last revised on May 14 and does not yet mention the new CVE.
Rapid7 notes that the bug is separate from the two peering authentication flaws fixed earlier this year, CVE-2026-20127 and CVE-2026-20182, which sat in the vdaemon service. It targets a different API authentication path, but the recurrence of authentication bypasses in internet-facing SD-WAN control components, Rapid7 says, reinforces the need for emergency remediation.
It is also Cisco’s fourth catalog entry in September, after Firewall Management Center on September 9, Secure Email Gateway on September 14 and Identity Services Engine on September 16, and its 18th of the year. We covered the Email Gateway flaw and the ISE flaw when they landed.
What to do now
- Find every Catalyst SD-WAN Manager you run, and keep any that are reachable from the internet off unsecured networks or limit them to known, trusted hosts.
- Run
request admin-techon each Manager, then upgrade to a fixed release from the table above. - Search both log files for
j_security_checkentries from unfamiliar addresses, and open a Severity 3 TAC case if anything looks wrong. - Federal agencies have until October 3. CISA’s entry also carries its forensic triage flag, which points to its Forensics Triage Requirements under BOD 26-04.








No Comment! Be the first one.