Cisco Catalyst SD-WAN Manager has a critical flaw in how it manages API session authentication. Improper handling of URI encoding in an HTTP request can bypass an authentication rule that is supposed to restrict a specific API endpoint. An unauthenticated remote attacker can send a crafted HTTP request and gain access to the API with admin privileges, affecting confidentiality, integrity, and availability (CVSS 9.8). Organizations that run Catalyst SD-WAN Manager are affected; the provided data does not list vulnerable or fixed version ranges. No public proof-of-concept is known and the issue is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Install Cisco's fixed release for Catalyst SD-WAN Manager as soon as it is available for your deployment; the supplied data does not name vulnerable or fixed versions. Until patched, keep the Manager API off the internet and limit it to trusted management networks, and review API logs for unexpected unauthenticated requests that reach admin-only endpoints.
Affected
Cisco Catalyst SD-WAN Manager
—
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
CISA Known Exploited Vulnerability
Affected
Cisco Catalyst SD-WAN Manager
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | Reversed by Horizon3 CVE-2026-76504 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to gain API access as the admin user. Cisco assigns it a CVSS 3.1 score of 9.8 and has confirmed active exploitation. CISA added the vulnerability to its Known…
Cisco says CVE-2026-76504, a critical SD-WAN Manager API authentication bypass, is being exploited in the wild.
On September 30, 2026, Cisco disclosed CVE-2026-76504, a CVSS 9.8 API authentication bypass in Cisco Catalyst SD-WAN Manager caused by improper URL-encoding handling. An unauthenticated remote attacker can send a crafted HTTP request and reach a specific API endpoint with admin privileges. Cisco says the flaw is being actively exploited, no workaround is available, and fixed on-premises releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Managed Cisco SD-WAN Cloud release 20.15.605 is already patched, and Rapid7 urges emergency upgrades plus log review.
Cisco released fixes for CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that unauthenticated attackers are actively exploiting to gain administrator privileges. Improper URI-encoding handling lets a crafted HTTP request skip an authentication rule on a specific API endpoint, and every deployment is affected regardless of configuration. Cisco PSIRT learned of exploitation in September 2026 and cited malicious use of %6a for the character "j" plus suspicious j_security_check entries in serviceproxy-access.log and vmanage-server.log. Fixed versions include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1; it is the fifth SD-WAN zero-day exploited in 2026, after CVE-2026-20127, CVE-2026-20182, CVE-2026-20245, and CVE-2026-20262.
Cisco reports active exploitation of critical CVE-2026-76504 (CVSS 9.8) unauthenticated authentication bypass in Catalyst SD-WAN Manager; patches released, no workaround.
Cisco disclosed CVE-2026-76504, a CVSS 9.8 flaw in Catalyst SD-WAN Manager that lets a remote unauthenticated attacker act as the admin user by sending a crafted HTTP request with mishandled URI encoding that bypasses an authentication rule. Cisco PSIRT became aware of active exploitation in September 2026 after the flaw was found during a TAC support case. First fixed releases span 20.9.10.1 through 26.2.1 depending on train, with no workaround; internet-exposed Managers are at risk of full compromise. CISA's KEV catalog already lists eight Cisco SD-WAN flaws added in 2026, and admins should check serviceproxy-access.log and vmanage-server.log for URI-encoded j_security_check requests (e.g., /%6a_security_check) from unknown IPs.
CISA added actively exploited Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 to the Known Exploited Vulnerabilities catalog.
CISA added CVE-2026-76504, a hex-encoding vulnerability in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The agency said this class of flaw is a frequent attack vector and poses significant risk to federal enterprises. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets. CISA encouraged all organizations to remediate cataloged flaws using risk-based vulnerability management.