TRENDING
Galvanized steel guardrail bolted to wooden posts along the edge of a bridge approach, with a grassy verge and a gravel road beside it
October 1, 2026
How to Enforce Guardrails on AI-Generated Terraform With Open Policy Agent and Rego
Microscope die shot of an AMD EPYC 7702 engineering sample I/O die, its circuit blocks glowing in teal, gold and violet
October 1, 2026
AMD Agrees to Buy Fei-Fei Li’s World Labs for $8.2 Billion to Steer Its Chip Roadmap
A silver signet ring engraved with a coat of arms between two sticks of red sealing wax on a grey surface
October 1, 2026
How to Build a Merkle Tree Certificate Issuer in Python to Keep Post-Quantum Certificates Small
Brass swing-bar door lock, a secondary latch, mounted on a hotel room door
October 1, 2026
Cloudflare’s Post-Quantum Visibility Turns Quantum Readiness Into a Per-Hop Audit
A seven-spot ladybird with black spots on its orange shell climbs a green plant stem
October 1, 2026
OpenAI Launches Dots, Always-On Agents, and Says It Is Still Fixing Known Vulnerabilities
01 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Faint white watermark of a crown above an oval emblem showing through blue paper, a design that stays invisible until light passes through the sheet
How to Detect and Strip Invisible Unicode in Python to Stop ASCII Smuggling and Trojan Source
September 30, 2026
A small white wooden toll booth with a Pay Point sign and a fare board at Penmaenpool Toll Bridge, with orange traffic cones on the bridge deck
Two Cloudflare Agent Billing Betas Turn Web Monetization Into a Question of Who Holds the Meter
September 30, 2026
Eight silver hex keys of graduated sizes fanned out on a steel ring against a dark green surface
Attackers Exploit a Hex-Encoding Bypass in Cisco SD-WAN Manager, and CISA Sets an October 3 Deadline
September 30, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 216 Posts
News 218 Posts
Learning Hub 188 Posts
Home/News/Attackers Exploit a Hex-Encoding Bypass in Cisco SD-WAN Manager, and CISA Sets an October 3 Deadline
News

Attackers Exploit a Hex-Encoding Bypass in Cisco SD-WAN Manager, and CISA Sets an October 3 Deadline

Cisco says attackers are exploiting CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager that a single hex-encoded character can trigger, and CISA has given federal agencies...

September 30, 2026 5 Min Read
7

Cisco says attackers are exploiting a critical authentication bypass in Catalyst SD-WAN Manager, the management console formerly known as vManage, and that encoding a single character of a login path is enough to trigger it. The flaw, CVE-2026-76504, carries a CVSS 3.1 base score of 9.8, needs no credentials, and lets a remote attacker use the Manager’s API as the admin user, according to Cisco’s advisory published on September 30, 2026. CISA added the bug to its Known Exploited Vulnerabilities catalog the same day and gave federal civilian agencies until Saturday, October 3, to act.

Table Of Content

  • One encoded character is enough
  • Which releases fix it
  • How to check whether a Manager was hit
  • Another SD-WAN entry on CISA’s list
  • What to do now

Cisco’s Product Security Incident Response Team (PSIRT) “became aware of active exploitation of this vulnerability” in September 2026, the advisory says, and the bug was found while Cisco resolved a Technical Assistance Center (TAC) support case. The advisory does not say how many customers were hit, when the attacks began, who is behind them or what the attackers did with the access.

One encoded character is enough

Cisco describes a flaw in the API session-based authentication management of SD-WAN Manager. In its words, the bug “is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint.” An attacker only has to send a crafted HTTP request to the Manager’s API.

The example in Cisco’s indicators of compromise shows the trick. The login path j_security_check, which The Hacker News describes as the path the Manager uses for session-based logins, is requested as /%6a_security_check, where %6a is the URI-encoded letter j. Cisco stresses that the letter is only an example and that the vulnerability “will allow any one character that is encoded in the request to be used to exploit this.”

MITRE files this class of mistake as CWE-177, Improper Handling of URL Encoding (Hex Encoding), and CISA’s catalog names the bug the Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability. The flaw affects the Manager “regardless of system configuration,” Cisco says. The Hacker News adds that the admin user holds the netadmin role by default, which is allowed to perform all operations on the device, and BleepingComputer describes the Manager as software that lets administrators monitor and manage up to 6,000 SD-WAN devices from a single dashboard.

At the time of writing, the National Vulnerability Database entry is still marked Undergoing Analysis. The 9.8 score and its vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, are Cisco’s own, while CISA’s entry in the record rates exploitation as active, the attack as automatable and the technical impact as total.

Which releases fix it

Cisco’s fixed releases are listed below. The company also fixed its cloud-based Cisco SD-WAN Cloud (Cisco Managed) service in release 20.15.605 and says no customer action is needed there.

Catalyst SD-WAN release First fixed release
Earlier than 20.9 Migrate to a fixed release
20.9 20.9.10.1
20.12 20.12.8.2
20.15 20.15.6.1
20.18 20.18.4.1
26.1 26.1.2.1
26.2 26.2.1

There is no workaround. For on-premises systems Cisco lists a mitigation instead: restrict access from unsecured networks such as the internet, allow only known, trusted hosts if internet access is required, and protect the control components behind a filtering device such as a firewall. Cisco says Cloud Hosted environments already have that mitigation in place, and Rapid7 still advises upgrading even where it is applied.

Patching for earlier 2026 flaws does not cover this one. Cisco’s advisory for the May flaw, CVE-2026-20182, lists 20.9.9.1, 20.12.7.1, 20.15.5.2, 20.18.2.2 and 26.1.1.1 as the latest fixed releases in those trains, and each is older than the matching release above. A Manager last upgraded for the May fix still needs this update.

The new table also omits trains that the May advisory covered: 20.10, 20.11, 20.13, 20.14 and 20.16, four of which that advisory footnoted as having reached End of Software Maintenance. It does not mention Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP) either, two deployment types the May advisory named as affected. Owners of those systems should confirm their path with Cisco or move to a listed train.

How to check whether a Manager was hit

Cisco points administrators to two log files. In /var/log/nms/containers/service-proxy/serviceproxy-access.log, look for j_security_check requests from unknown or unauthorized IP addresses, such as this request from Cisco’s example, which was answered with HTTP 200:

POST /%6a_security_check HTTP/1.1

In /var/log/nms/vmanage-server.log, look for j_security_check entries tied to users whose names start with viptela-reserved-, the prefix of the system service accounts Cisco documents in its configuration guide. Cisco’s example reads:

Request Stored in Map is (/%6a_security_check) for user (viptela-reserved-..)

Cisco warns that these entries can also appear during standard operations and must be assessed against normal network posture to avoid false positives. Because any one encoded character works, a search for %6a alone can miss variants. For help determining whether a Manager was compromised, Cisco says customers may open a Severity 3 TAC case with CVE-2026-76504 in the title, and encourages them to run request admin-tech on the Manager first so the file can be reviewed.

The new advisory does not say whether upgrading removes an attacker who is already inside. Cisco’s May advisory was explicit. It told customers to run request admin-tech on each control component before upgrading, to preserve possible indicators of compromise, and warned that on a system confirmed to be compromised “applying the software update alone will not resolve the vulnerability.” Collecting the admin-tech file first is a cheap way to keep the evidence.

Another SD-WAN entry on CISA’s list

Counted from CISA’s JSON feed, the catalog now holds nine Cisco SD-WAN entries, all added in 2026: CVE-2026-20127 and CVE-2022-20775 on February 25, CVE-2026-20122, CVE-2026-20133 and CVE-2026-20128 on April 20, CVE-2026-20182 on May 14, CVE-2026-20245 on June 9, CVE-2026-20262 on June 15, and now CVE-2026-76504. BleepingComputer counts the new bug as the fifth SD-WAN zero-day exploited this year. After the earlier exploitation, CISA issued Emergency Directive 26-03, which requires federal civilian agencies to inventory their Cisco SD-WAN systems, update them and assess compromise, according to CISA’s SD-WAN alert. That alert was last revised on May 14 and does not yet mention the new CVE.

Rapid7 notes that the bug is separate from the two peering authentication flaws fixed earlier this year, CVE-2026-20127 and CVE-2026-20182, which sat in the vdaemon service. It targets a different API authentication path, but the recurrence of authentication bypasses in internet-facing SD-WAN control components, Rapid7 says, reinforces the need for emergency remediation.

It is also Cisco’s fourth catalog entry in September, after Firewall Management Center on September 9, Secure Email Gateway on September 14 and Identity Services Engine on September 16, and its 18th of the year. We covered the Email Gateway flaw and the ISE flaw when they landed.

What to do now

  1. Find every Catalyst SD-WAN Manager you run, and keep any that are reachable from the internet off unsecured networks or limit them to known, trusted hosts.
  2. Run request admin-tech on each Manager, then upgrade to a fixed release from the table above.
  3. Search both log files for j_security_check entries from unfamiliar addresses, and open a Severity 3 TAC case if anything looks wrong.
  4. Federal agencies have until October 3. CISA’s entry also carries its forensic triage flag, which points to its Forensics Triage Requirements under BOD 26-04.

Tags:

Authentication BypassCISA KEVCiscoNetwork SecuritySD-WANZero-Day

Share

Galvanized steel guardrail bolted to wooden posts along the edge of a bridge approach, with a grassy verge and a gravel road beside it
Previous Post

How to Enforce Guardrails on AI-Generated Terraform With Open Policy Agent and Rego

A small white wooden toll booth with a Pay Point sign and a fare board at Penmaenpool Toll Bridge, with orange traffic cones on the bridge deck
Next Post

Two Cloudflare Agent Billing Betas Turn Web Monetization Into a Question of Who Holds the Meter

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
30 Sep
How to Detect and Strip Invisible Unicode in Python to Stop ASCII Smuggling and Trojan Source
30 Sep
Two Cloudflare Agent Billing Betas Turn Web Monetization Into a Question of Who Holds the Meter
Trending
September 30, 2026
How to Detect and Strip Invisible Unicode in Python to Stop ASCII Smuggling and Trojan Source
September 30, 2026
Two Cloudflare Agent Billing Betas Turn Web Monetization Into a Question of Who Holds the Meter
September 30, 2026
Attackers Exploit a Hex-Encoding Bypass in Cisco SD-WAN Manager, and CISA Sets an October 3 Deadline
September 30, 2026
How to Enforce Guardrails on AI-Generated Terraform With Open Policy Agent and Rego
September 30, 2026
AMD Agrees to Buy Fei-Fei Li’s World Labs for $8.2 Billion to Steer Its Chip Roadmap
September 29, 2026
How to Build a Merkle Tree Certificate Issuer in Python to Keep Post-Quantum Certificates Small

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026