---
schema: 1
kind: vulnerability
title: "CVE-2026-76504, Cisco Catalyst SD-WAN Manager: one percent-encoded character in the login path skips the password check and mints an admin API session, exploited in the wild (CVSS 9.8)"
headline: "Cisco confirms exploitation of an unauthenticated admin bypass in the SD-WAN controller; no workaround, fixes per train"
summary: >
  Cisco's advisory of 2026-09-30 fixes CVE-2026-76504, an unauthenticated authentication bypass in the
  API of Cisco Catalyst SD-WAN Manager (formerly vManage) that gives an attacker the privileges of the admin user,
  regardless of configuration. Cisco says it became aware of exploitation in September 2026 and CISA added the flaw to
  its KEV catalog the same day; Cisco lists no workaround, and NCSC Switzerland published its own advisory.
discovered_at: "2026-10-02T04:44:00Z"
updated_at: null
event_date: "2026-09-30"
run_id: 2026-10-02T0404Z-intel
priority: critical
immediate_action:
  title: "Patch or take offline every internet-reachable Catalyst SD-WAN Manager now"
  action: >
    Cisco confirms in-the-wild exploitation of an unauthenticated admin-level API bypass in Catalyst SD-WAN Manager
    and offers no workaround. Upgrade to the first fixed release of the train (20.9.10.1, 20.12.8.2, 20.15.6.1,
    20.18.4.1, 26.1.2.1 or 26.2.1), restrict the Manager's web and API access to known trusted hosts behind a firewall
    in the meantime, and open a Severity 3 TAC case with the CVE id in the title for any Manager whose logs show the
    encoded login-path pattern.
tags: [vulnerabilities, auth-bypass, pre-auth, actively-exploited, cisa-kev, patch-available]
regions: [global, switzerland]
sectors: [public-sector, technology]
entities: ["product:cisco-catalyst-sd-wan-manager"]
techniques: [T1190]
affected_products: ["Cisco Catalyst SD-WAN Manager"]
cves:
  - id: CVE-2026-76504
    cvss: "9.8"
    epss: 0.01096
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "Cisco Catalyst SD-WAN Manager regardless of configuration, every release before the first fixed release of its train; releases earlier than 20.9 must migrate to a fixed train"
    fixed: "20.9.10.1; 20.12.8.2; 20.15.6.1; 20.18.4.1; 26.1.2.1; 26.2.1 (the Cisco-managed cloud service was fixed in release 20.15.605, no customer action)"
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU"
    publisher: "Cisco PSIRT"
    date: "2026-09-30"
    role: primary
  - url: "https://www.vulncheck.com/blog/revenge-of-the-sd-wan-cve-2026-76504"
    publisher: "VulnCheck"
    date: "2026-10-01"
    role: corroborating
  - url: "https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog"
    publisher: "CISA"
    date: "2026-09-30"
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/13021"
    publisher: "NCSC Switzerland (Cyber Security Hub)"
    date: "2026-09-30"
    role: corroborating
closed_sources: []
evidence:
  - quote: "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability."
    publisher: "Cisco PSIRT"
    source_url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU"
  - quote: "This vulnerability affects Cisco Catalyst SD-WAN Manager, regardless of system configuration."
    publisher: "Cisco PSIRT"
    source_url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU"
  - quote: "there are no legitimate public exploits for CVE-2026-76504 as of October 1, 2026"
    publisher: "VulnCheck"
    source_url: "https://www.vulncheck.com/blog/revenge-of-the-sd-wan-cve-2026-76504"
verification: multi-source
sourcing_note: >
  Exploitation is Cisco's own statement; CISA's KEV listing and NCSC Switzerland's advisory act on it and are not
  independent observations. VulnCheck reproduced the flaw independently; the mechanism below is VulnCheck's reading of the
  decompiled login module, not Cisco's.
confidence: high
references:
  - 2026-06-06/cve-2026-20245-cisco-catalyst-sd-wan-manager-actively-exploi
  - 2026-05-15/cve-2026-20182-cisco-catalyst-sd-wan-controller-manager-pre
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Upgrade every Catalyst SD-WAN Manager to the first fixed release of its train (20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1; anything earlier than 20.9 must migrate) and, until the upgrade is done, restrict the Manager's web and API access to known trusted hosts behind a firewall."
  - "On every Manager that was internet-reachable before the upgrade, run the compromise check described in the body and open a Severity 3 Cisco TAC case with the CVE id in the title if anything matches."
updates: []
migrated_from: null
---

Cisco published an advisory on 2026-09-30 for CVE-2026-76504, an authentication bypass in the API session management of Cisco Catalyst SD-WAN Manager that lets an unauthenticated remote attacker reach the API with the privileges of the admin user ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)). Cisco states its PSIRT became aware of active exploitation in September 2026 ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)), CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day ([CISA, 2026-09-30](https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog)), and no source names an actor. The flaw affects the Manager regardless of configuration and Cisco lists no workaround ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)).

VulnCheck's reproduction explains the mechanism. The application server decodes the request path when it matches its login security constraint, but Cisco's login module tests the raw, undecoded path for the string `j_security_check` before it decides whether to run the real password check, so a request to `/%6a_security_check` skips the password check ([VulnCheck, 2026-10-01](https://www.vulncheck.com/blog/revenge-of-the-sd-wan-cve-2026-76504)). The request then falls into a branch written for continuing an already trusted session, whose only gate is a substring match against four internal `viptela-reserved-` account names, and supplying any of them builds a fresh login session ([VulnCheck, 2026-10-01](https://www.vulncheck.com/blog/revenge-of-the-sd-wan-cve-2026-76504)). Two of the four accounts hit role checks on admin-only endpoints and two are expected to carry the needed permissions ([VulnCheck, 2026-10-01](https://www.vulncheck.com/blog/revenge-of-the-sd-wan-cve-2026-76504)). Cisco stresses that any single encoded character works, not only `%6a` ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)). VulnCheck counts about 1,500 internet-exposed Managers and found no legitimate public exploit as of 2026-10-01; it rejected a fake proof-of-concept repository ([VulnCheck, 2026-10-01](https://www.vulncheck.com/blog/revenge-of-the-sd-wan-cve-2026-76504)).

Cisco's first fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; releases earlier than 20.9 must migrate to a fixed train, and the Cisco-managed cloud service (release 20.15.605) needed no customer action ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)). NCSC Switzerland posted its own advisory on 2026-09-30 and lists the flaw as actively exploited ([NCSC Switzerland, 2026-09-30](https://security-hub.ncsc.admin.ch/#/posts/13021)).

**Exposure:** an on-premises Manager whose web or API listener is reachable from the internet or from untrusted segments; Cisco says Managers exposed to the internet with open ports are at risk, and fixed releases exist for the 20.9 and later trains, while earlier releases must migrate ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)).

**Detection:** in web and application access logs on the Manager, Cisco names two sources: `serviceproxy-access.log` (under `/var/log/nms/containers/service-proxy/`) for POSTs to the login path with an encoded character from unknown or unauthorized addresses, and `vmanage-server.log` for lines about that path tied to usernames starting `viptela-reserved-` ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)). To judge whether a Manager was already accessed, Cisco directs customers to open a Severity 3 TAC case with the CVE id in the title and to attach the output of `request admin-tech` ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)).

**Triage:** Cisco warns that these log entries can also occur during standard operation and must be assessed against normal network posture; a `viptela-reserved-` name is an internal service account, so the signal is a login-path request with an encoded character from an address that is not part of the fabric ([Cisco PSIRT, 2026-09-30](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU)).

**Defender takeaway:** upgrade to the fixed release of the train now and remove internet reachability of the Manager in the meantime (known trusted hosts only, behind a filtering device, per Cisco's hardening guide); a Manager that was reachable and unpatched needs the log review and TAC check above before it is considered clean.
