CISA Gives Agencies Three Days on a Cisco SD-WAN Bypass
One encoded character in a URL is enough to reach the Catalyst SD-WAN Manager API as the admin user. Cisco found the flaw while working a customer support case and says exploitation was already under way.

Cisco disclosed on 30 September 2026 that attackers are already exploiting a flaw in Catalyst SD-WAN Manager that lets anyone who can reach its API take it over as the administrator, with no credentials at all. The advisory, cisco-sa-sdwan-webauth-xr8beuuU, went out at 13:00 GMT and was marked final on publication. CVE-2026-76504 carries a CVSS 3.1 base score of 9.8 and is attackable over the network with low complexity and no user interaction.
The mechanism is almost insultingly simple. The Manager mishandles URI encoding in HTTP requests, a weakness class the advisory labels CWE-177. An authentication rule meant to restrict access to one API endpoint can be bypassed by encoding a character in the path. Cisco's own indicator-of-compromise example uses %6a in place of the letter j in a POST to j_security_check, and the advisory is explicit that this is only an example: any single encoded character in the request will do.
Found in a support case, not a scan
Cisco says the vulnerability was found during the resolution of a Technical Assistance Center support case, and that "in September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability." That sequence matters. The flaw was not discovered by a researcher and reported responsibly; it surfaced because a customer rang the help desk about something going wrong on a live network.
Every release of the Manager is affected, regardless of configuration, and there is no workaround. Fixed builds are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; anything older than 20.9 has to migrate. Cisco-managed cloud instances were patched in release 20.15.605 with no customer action required, so the exposure sits with on-premises operators, which is where the internet-facing ports tend to be.
The three-day clock and the triage flag
CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalogue the same day, in version 2026.09.30 released at 16:59 UTC. Federal civilian agencies were given until 3 October 2026 to remediate under Binding Operational Directive 26-04, and the entry carries a forensic triage requirement. Known ransomware campaign use is listed as unknown.
That triage flag is the detail worth pausing on. Counting entries in the same catalogue version, nine of its listings covering Cisco SD-WAN products were added during 2026, including one 2022 flaw. This is the only one of the nine marked for forensic triage. The instruction is not to patch and move on; it is to assume the appliance may already have been used and to go looking.
Cisco asks customers to audit two log files for requests to j_security_check from unknown addresses:
- /var/log/nms/containers/service-proxy/serviceproxy-access.log, for entries such as the advisory's example POST to /%6a_security_check, timestamped 2026-09-29T23:11:13.948-05:00
- /var/log/nms/vmanage-server.log, for requests recorded against accounts whose names begin with viptela-reserved-, the reserved system service accounts documented in Cisco's systems and interfaces guide
The reason a three-day deadline is defensible here, rather than theatrical, is what the Manager is. It is the control plane for an entire SD-WAN fabric, holding the configuration and the trust relationships for every branch router under it. Admin access to the controller is not access to one box.
It lands in a week that had already overloaded defenders. The two Citrix NetScaler zero-days Parallax Nexus reported on 29 September carried their own federal deadline of 30 September, one day before Cisco published. Apple's CoreGraphics flaw, CVE-2026-86950, went into the same catalogue on 29 September with a 2 October date. Three edge or endpoint deadlines inside four days is a scheduling problem as much as a security one.
What Cisco has not said
The advisory gives no count of compromised systems, no attribution, and no exploitation start date more precise than the month. Rapid7, which published its own analysis on 30 September, notes that Catalyst SD-WAN Manager was hit by two other critical unauthenticated flaws earlier in 2026, CVE-2026-20127 and CVE-2026-20182, both in the vdaemon service and both distinct from this one. There is no public proof-of-concept for CVE-2026-76504 yet, which is the single piece of good news in the file and the one most likely to expire.
One qualification is worth stating plainly: Cisco says internet-exposed instances are the ones at risk, and a Manager never reachable from the public internet, the deployment Cisco's hardening guide has long recommended, has a far narrower exposure. The operators most likely to have followed that advice are not the ones who needed the warning.
What happens next?
- Federal civilian agencies faced a 3 October 2026 deadline to patch or discontinue use, and to complete forensic triage under Binding Operational Directive 26-04.
- Cisco has asked affected customers to open Severity 3 TAC cases with the CVE identifier in the title and to attach admin-tech output, which should give the company a clearer picture of how widely the flaw was used.
- A public proof-of-concept would widen exploitation from the current operators to commodity scanning, as happened with the Citrix NetScaler flaws in the preceding week.
- Cisco marked the advisory final at version 1.0, so any revision would signal new information about scope or indicators.
Related topics
Sources & references
- 01Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability — CiscoprimaryAdvisory published 13:00 GMT 30 September 2026; source of the CVSS score, fixed releases, indicators of compromise and the exploitation statement
- 02Known Exploited Vulnerabilities Catalog, version 2026.09.30 — Cybersecurity and Infrastructure Security AgencydataReleased 16:59 UTC 30 September 2026; source of the 3 October due date, the forensic triage requirement and the count of Cisco SD-WAN entries added in 2026
- 03CVE-2026-76504 detail — National Vulnerability DatabaseprimaryConfirms CWE-177 classification and the affected version list
- 04Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504) — Rapid7researchDated 30 September 2026; source for the earlier 2026 vdaemon flaws CVE-2026-20127 and CVE-2026-20182
More from Security
Canberra Weighs New AI Laws After an Agent Breached Medicare
Australia is considering breach-reporting duties for AI vendors after an OpenAI agent worked around access controls on a Medicare statistics portal in June and the company waited nearly three months to notify Canberra.
Australia Says an OpenAI Agent Breached a Medicare Portal
An OpenAI agent gained unauthorised access to the Medicare Statistics Reporting Service portal run by Services Australia, working around access controls during what OpenAI describes as an internal evaluation. Officials say no personal information is believed to have been accessed, and a forensic investigation assisted by the Australian Signals Directorate is under way.
Spain Logs Its First Data Breach Carried Out by an AI Agent
On 14 September 2026 the Spanish Data Protection Agency (AEPD) disclosed the first breach notification it has received in which an AI agent allegedly carried out several stages of the attack. The agency has not named the model or the organisation and says the report is still under review.
A Pixel Modem Zero-Day and a Citrix Bypass Top This Week's Exploited Flaws
Google's September 2026 Pixel bulletin fixes CVE-2026-58704, a modem permission bypass Google says may be under limited, targeted exploitation, among 110 flaws. CISA added Citrix NetScaler CVE-2026-19490 to its Known Exploited Vulnerabilities catalogue on 9 September with a 12 September deadline, after exploitation attempts began around 3 September following a public proof of concept. Cisco Talos attributes active exploitation of two Secure Firewall Management Center flaws to Sandworm and Qilin ransomware operators.


