CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
CRITICALCVE-2026-76504exploitedNATOA1vulnerability

CVE-2026-76504, Cisco Catalyst SD-WAN Manager: one percent-encoded character in the login path skips the password check and mints an admin API session, exploited in the wild (CVSS 9.8)

Cisco confirms exploitation of an unauthenticated admin bypass in the SD-WAN controller; no workaround, fixes per train

Defender actions

  • Upgrade every Catalyst SD-WAN Manager to the first fixed release of its train (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1; anything earlier than 20.9 must migrate) and, until the upgrade is done, restrict the Manager's web and API access to known trusted hosts behind a firewall.
  • On every Manager that was internet-reachable before the upgrade, run the compromise check described in the body and open a Severity 3 Cisco TAC case with the CVE id in the title if anything matches.

Analysis

Cisco published an advisory on 2026-09-30 for CVE-2026-76504, an authentication bypass in the API session management of Cisco Catalyst SD-WAN Manager that lets an unauthenticated remote attacker reach the API with the privileges of the admin user (Cisco PSIRT, 2026-09-30). Cisco states its PSIRT became aware of active exploitation in September 2026 (Cisco PSIRT, 2026-09-30), CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day (CISA, 2026-09-30), and no source names an actor. The flaw affects the Manager regardless of configuration and Cisco lists no workaround (Cisco PSIRT, 2026-09-30).

VulnCheck's reproduction explains the mechanism. The application server decodes the request path when it matches its login security constraint, but Cisco's login module tests the raw, undecoded path for the string j_security_check before it decides whether to run the real password check, so a request to /%6a_security_check skips the password check (VulnCheck, 2026-10-01). The request then falls into a branch written for continuing an already trusted session, whose only gate is a substring match against four internal viptela-reserved- account names, and supplying any of them builds a fresh login session (VulnCheck, 2026-10-01). Two of the four accounts hit role checks on admin-only endpoints and two are expected to carry the needed permissions (VulnCheck, 2026-10-01). Cisco stresses that any single encoded character works, not only %6a (Cisco PSIRT, 2026-09-30). VulnCheck counts about 1,500 internet-exposed Managers and found no legitimate public exploit as of 2026-10-01; it rejected a fake proof-of-concept repository (VulnCheck, 2026-10-01).

Cisco's first fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; releases earlier than 20.9 must migrate to a fixed train, and the Cisco-managed cloud service (release 20.15.605) needed no customer action (Cisco PSIRT, 2026-09-30). NCSC Switzerland posted its own advisory on 2026-09-30 and lists the flaw as actively exploited (NCSC Switzerland, 2026-09-30).

Exposure: an on-premises Manager whose web or API listener is reachable from the internet or from untrusted segments; Cisco says Managers exposed to the internet with open ports are at risk, and fixed releases exist for the 20.9 and later trains, while earlier releases must migrate (Cisco PSIRT, 2026-09-30).

Triage: Cisco warns that these log entries can also occur during standard operation and must be assessed against normal network posture; a viptela-reserved- name is an internal service account, so the signal is a login-path request with an encoded character from an address that is not part of the fabric (Cisco PSIRT, 2026-09-30).

Cited evidence

In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

This vulnerability affects Cisco Catalyst SD-WAN Manager, regardless of system configuration.

Cisco PSIRT 2026-09-30

there are no legitimate public exploits for CVE-2026-76504 as of October 1, 2026

VulnCheck 2026-10-01

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.