CVE-2026-76504: Cisco SD-WAN Flaw Exploited
Cisco has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Catalyst SD-WAN Manager, formerly known as vManage. The flaw allows an unauthenticated remote attacker to access the management API with administrator privileges.
Cisco confirmed active exploitation in September 2026 and assigned the vulnerability a CVSS 3.1 score of 9.8 (Critical). CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on September 30, setting an October 3, 2026 remediation deadline for covered federal agencies.
What Is CVE-2026-76504?
CVE-2026-76504 is an authentication bypass vulnerability affecting API session-based authentication management in Cisco Catalyst SD-WAN Manager.
The issue stems from improper handling of URI encoding, classified as CWE-177: Improper Handling of URL Encoding (Hex Encoding). Inconsistent interpretation of encoded characters can allow a specially crafted HTTP request to bypass an authentication rule protecting a specific API endpoint.
Successful exploitation gives an unauthenticated attacker access to the management API with the privileges of the administrator account.
According to Cisco’s security advisory, the vulnerability affects deployments regardless of system configuration. It does not require valid credentials or user interaction.
The flaw carries the following CVSS vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details of CVE-2026-76504 (SOCRadar Free Tools, CVE Intelligence)
Which Cisco Catalyst SD-WAN Versions Are Affected?
Cisco released fixes on September 30, 2026. The following table lists the first fixed releases for each affected branch:
| Cisco SD-WAN Release | First Fixed Release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Releases earlier than 20.9 have reached the end of software maintenance and require migration to a supported, fixed release.
Cisco also addressed the vulnerability in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605. Customers using this managed service do not need to perform the upgrade themselves but can verify remediation status through the Help function in the service interface.
For customer-managed deployments, administrators should consult Cisco’s compatibility and upgrade matrices before selecting the appropriate release.
How Does CVE-2026-76504 Work?
The vulnerable component handles API session-based authentication in Catalyst SD-WAN Manager.
An attacker can exploit inconsistent URI decoding to make a request reach an endpoint that should be protected by an authentication rule. Cisco identified encoded characters in requests associated with j_security_check as an indicator of possible exploitation.
For example, Cisco documented requests containing %6a, the encoded representation of the letter j. However, the vendor warns that other encoded characters may also be used.
This weakness is particularly significant because Catalyst SD-WAN Manager operates within the network management plane. Administrator-level API access may expose operational information and management functions across the SD-WAN deployment.
However, the advisory establishes administrator-level API access through authentication bypass, not direct operating-system remote code execution. Any subsequent impact depends on the deployment and the attacker’s actions after gaining access.
Is CVE-2026-76504 Being Actively Exploited?
Yes. Cisco has confirmed exploitation in the wild.
Cisco’s Product Security Incident Response Team (PSIRT) became aware of active exploitation in September 2026. The company published its security advisory on September 30 and strongly recommended upgrading affected deployments.
CISA subsequently added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on the same day. The listing assigns an October 3, 2026 remediation deadline for federal agencies subject to CISA’s applicable requirements. It also calls for forensic triage under the agency’s BOD 26-04 implementation guidance.
Cisco has not publicly attributed the activity to a specific threat actor or disclosed the full scope of confirmed compromises. The advisory also does not establish that every vulnerable installation has been exploited.
Is a Public Proof of Concept Available?
As of October 1, 2026, publicly indexed repositories referencing CVE-2026-76504 have appeared, but a reliable, independently verified working public exploit has not been observed.
Cisco has published detection guidance and Snort rule 67179. These are defensive resources rather than proof-of-concept (PoC) exploits.
Regardless of public PoC availability, vendor-confirmed exploitation makes remediation urgent.
Track CVE-2026-76504 with SOCRadar
With active exploitation confirmed, organizations need timely intelligence to understand the threat and identify affected infrastructure.
Powered by SOCRadar’s Cyber Threat Intelligence module, Vulnerability Intelligence provides consolidated vulnerability intelligence, including severity, exploitation status, CISA KEV information, and remediation context. The module further supports threat tracking by correlating emerging vulnerabilities with threat actor activity, campaigns, and relevant intelligence.
Combined with Attack Surface Management, these capabilities can help security teams identify externally exposed Cisco infrastructure, prioritize vulnerable management interfaces, and monitor new exploitation developments while remediation proceeds.

SOCRadar’s Vulnerability Intelligence
What Should Defenders Do About CVE-2026-76504?
Cisco has published a dedicated Catalyst SD-WAN remediation workflow recommending evidence collection, immediate upgrading, and compromise assessment through Cisco TAC.
1. Collect Evidence and Apply the Fix
Start by identifying every affected Catalyst SD-WAN Manager instance, including cluster members and disaster recovery deployments.
Cisco recommends the following sequence:
- Collect admin-tech files from every Manager before upgrading, selecting the Log and Tech options. Core collection is not required.
- Upgrade all affected Managers to the applicable fixed release.
- Open a Severity 3 Cisco TAC case with CVE-2026-76504 in the title.
- Submit the collected admin-tech bundles so TAC can scan them for indicators of compromise.
Do not wait for TAC scan results before upgrading. Cisco explicitly identifies installing the fixed release as the highest remediation priority once evidence has been collected.
Cisco also advises remaining within the current major release during the upgrade unless TAC explicitly recommends otherwise. Earlier releases that have reached the end of maintenance require migration planning.
2. Reduce Exposure While Patching
Cisco states that no workaround fully addresses CVE-2026-76504. However, organizations can temporarily reduce exposure by:
- Removing unnecessary internet access to Catalyst SD-WAN Manager.
- Restricting management access to known, trusted hosts.
- Placing SD-WAN control components behind appropriate firewall controls.
- Allowing only required ports and protocols between authorized systems.
These controls can limit an attacker’s ability to reach the vulnerable service but should not replace the software upgrade.
3. Review Administrator Accounts and Logging
Cisco additionally recommends strengthening the security of management accounts and related infrastructure.
Administrators should change default passwords, enforce appropriately scoped access, use operator accounts where suitable, and deploy trusted TLS certificates.
Forwarding logs to an external system can also improve evidence retention, particularly if the Manager itself becomes compromised or undergoes disruptive maintenance.
How Can Teams Detect and Hunt for CVE-2026-76504?
Cisco has published indicators associated with suspicious authentication requests. Defenders should review available logs, preserve relevant findings, and correlate unusual requests with subsequent administrative activity.
Review Authentication Logs
Cisco identifies two important log sources:
| Log | What to Investigate |
|---|---|
| serviceproxy-access.log | Encoded requests associated with j_security_check originating from unknown or unauthorized IP addresses |
| vmanage-server.log | Suspicious authentication requests involving reserved system users, including names beginning with viptela-reserved- |
In particular, search for encoded authentication paths such as /%6a_security_check, while remembering that %6a is only one example. Cisco warns that other URI characters may be encoded to trigger the vulnerability.
Review current and rotated logs where available, including records from cluster members and disaster recovery Managers.
Some relevant files may require privileged access. Cisco therefore prefers admin-tech collection over relying exclusively on manual log inspection.
Correlate Suspicious Activity
Security teams should investigate:
- Requests to authentication endpoints from unfamiliar source IP addresses.
- Unexpected administrator sessions or account activity.
- Changes to SD-WAN Manager configuration following suspicious requests.
- Unusual network access to the management interface.
- Gaps or unexplained changes in historical logs.
Where supported, Snort rule 67179 can provide additional detection coverage.
Cisco cautions that some published indicators may also occur during legitimate activity. Suspicious requests should be assessed against normal network behavior, and a clean search does not independently establish that a previously exposed system was never compromised.
Submit Evidence to Cisco TAC
Cisco recommends collecting admin-tech bundles from all affected Managers, not only those showing obvious suspicious activity.
After upgrading, submit the bundles through a TAC case for compromise assessment. If Cisco identifies indicators of compromise, follow its environment-specific remediation guidance.
Given the confirmed exploitation and CISA’s October 3 federal deadline, organizations should prioritize upgrading vulnerable deployments while preserving the evidence needed to investigate possible earlier access.

