CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Cisco Catalyst SD-WAN Manager, authentication bypass (CVSS 9.8), exploited, in CISA KEV

cve · CVE-2026-76504

Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Cisco confirms exploitation of an unauthenticated admin bypass in the SD-WAN controller; no workaround, fixes…
Peak priority
critical
1 critical
Targets
public-sector
sectors: public-sector, technology · regions: switzerland
Sources cited
4
4 hosts

Action items (3)

Do-now tasks recorded on the entries about CVE-2026-76504, newest first. Check the date before acting on an older one.

  • Immediate action: Cisco confirms in-the-wild exploitation of an unauthenticated admin-level API bypass in Catalyst SD-WAN Manager and offers no workaround. Upgrade to the first fixed release of the train (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1), restrict the Manager's web and API access to known trusted hosts behind a firewall in the meantime, and open a Severity 3 TAC case with the CVE id in the title for any Manager whose logs show the encoded login-path pattern.
    2026-10-02CVE-2026-76504
  • Upgrade every Catalyst SD-WAN Manager to the first fixed release of its train (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1; anything earlier than 20.9 must migrate) and, until the upgrade is done, restrict the Manager's web and API access to known trusted hosts behind a firewall.
    2026-10-02CVE-2026-76504
  • On every Manager that was internet-reachable before the upgrade, run the compromise check described in the body and open a Severity 3 Cisco TAC case with the CVE id in the title if anything matches.
    2026-10-02CVE-2026-76504

Defender insights

What each entry about CVE-2026-76504 tells a defender to do, newest first.

2026-10-02CRITICALexploitedCisco confirms exploitation of an unauthenticated admin bypass in the SD-WAN controller; no workaround, fixes per train

Triage · detection

Story timeline

  1. 2026-10-02CVE-2026-76504, Cisco Catalyst SD-WAN Manager: one percent-encoded character in the login path skips the password check and mints an admin API session, exploited in the wild (CVSS 9.8)
    trending-vulnerabilitiesCisco confirms exploitation of an unauthenticated admin bypass in the SD-WAN controller; no workaround, fixes per train
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-02/cve-2026-76504-cisco-catalyst-sd-wan-manager-auth-bypass-kev · ATT&CK page ↗

Entries about Cisco Catalyst SD-WAN Manager, authentication bypass (CVSS 9.8), exploited, in CISA KEV (1)

2026-10-02 · view entry permalink →

CRITICALCVE-2026-76504exploitedNATOA1

CVE-2026-76504, Cisco Catalyst SD-WAN Manager: one percent-encoded character in the login path skips the password check and mints an admin API session, exploited in the wild (CVSS 9.8)

Cisco published an advisory on 2026-09-30 for CVE-2026-76504, an authentication bypass in the API session management of Cisco Catalyst SD-WAN Manager that lets an unauthenticated remote attacker reach the API with the privileges of the admin user (Cisco PSIRT, 2026-09-30). Cisco states its PSIRT became aware of active exploitation in September 2026 (Cisco PSIRT, 2026-09-30), CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day (CISA, 2026-09-30), and no source names an actor. The flaw affects the Manager regardless of configuration and Cisco lists no workaround (Cisco PSIRT, 2026-09-30).

VulnCheck's reproduction explains the mechanism. The application server decodes the request path when it matches its login security constraint, but Cisco's login module tests the raw, undecoded path for the string j_security_check before it decides whether to run the real password check, so a request to /%6a_security_check skips the password check (VulnCheck, 2026-10-01). The request then falls into a branch written for continuing an already trusted session, whose only gate is a substring match against four internal viptela-reserved- account names, and supplying any of them builds a fresh login session (VulnCheck, 2026-10-01). Two of the four accounts hit role checks on admin-only endpoints and two are expected to carry the needed permissions (VulnCheck, 2026-10-01). Cisco stresses that any single encoded character works, not only %6a (Cisco PSIRT, 2026-09-30). VulnCheck counts about 1,500 internet-exposed Managers and found no legitimate public exploit as of 2026-10-01; it rejected a fake proof-of-concept repository (VulnCheck, 2026-10-01).

Cisco's first fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; releases earlier than 20.9 must migrate to a fixed train, and the Cisco-managed cloud service (release 20.15.605) needed no customer action (Cisco PSIRT, 2026-09-30). NCSC Switzerland posted its own advisory on 2026-09-30 and lists the flaw as actively exploited (NCSC Switzerland, 2026-09-30).

Exposure: an on-premises Manager whose web or API listener is reachable from the internet or from untrusted segments; Cisco says Managers exposed to the internet with open ports are at risk, and fixed releases exist for the 20.9 and later trains, while earlier releases must migrate (Cisco PSIRT, 2026-09-30).

Triage: Cisco warns that these log entries can also occur during standard operation and must be assessed against normal network posture; a viptela-reserved- name is an internal service account, so the signal is a login-path request with an encoded character from an address that is not part of the fabric (Cisco PSIRT, 2026-09-30).

In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

This vulnerability affects Cisco Catalyst SD-WAN Manager, regardless of system configuration.

Cisco PSIRT 2026-09-30

there are no legitimate public exploits for CVE-2026-76504 as of October 1, 2026

VulnCheck 2026-10-01

Builds on: CVE-2026-20245, Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no… · CVE-2026-20182, Cisco Catalyst SD-WAN Controller/Manager: pre-auth authentication bypass…

vulnerability02 Oct 04:44Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • cisa.gov1 (25%)
  • sec.cloudapps.cisco.com1 (25%)
  • security-hub.ncsc.admin.ch1 (25%)
  • vulncheck.com1 (25%)