> ## Content Index
> Fetch the complete content index at: https://blog.previdian.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2026-76504: Critical Cisco Catalyst SD-WAN Manager Authentication Bypass Exploited in the Wild
- URL: https://blog.previdian.com/cve-2026-76504-critical-cisco-catalyst-sd-wan-manager-authentication-bypass-exploited-in-the-wild/
- Published: 2026-09-30T16:09:30.000Z
- Updated: 2026-09-30T16:09:30.000Z
- Author: Ryan Dewhurst

Cisco has disclosed [CVE-2026-76504](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com), a critical unauthenticated authentication bypass affecting [Cisco Catalyst SD-WAN Manager](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com), formerly known as Cisco vManage.

The vulnerability carries a **CVSS v3.1 score of 9.8**, requires no authentication or user interaction, and can give a remote attacker API access with administrator privileges. Most importantly, [Cisco has confirmed that CVE-2026-76504 is being actively exploited](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com).

The disclosure also confirms an [early warning for CVE-2026-76504](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com) that Previdian sent to customers earlier on 30 September, before official technical details were available.

What initially appeared as an unconfirmed rumour about a serious Cisco SD-WAN vulnerability has now developed into a critical vulnerability with confirmed real-world exploitation.

## The warning before the disclosure

Earlier on 30 September, a [report in the Cisco community on Reddit](https://www.reddit.com/r/Cisco/comments/1wtoqxx/yet%5Fanother%5Fsdwan%5Fvulnerability%5F30%5Fseptember/?utm%5Fsource=chatgpt.com) warned that a substantial Cisco SD-WAN vulnerability was expected to be announced later that day.

At the time, there was **no CVE, Cisco security advisory, technical detail, or official confirmation of exploitation**.

Previdian treated the report as an early signal rather than a confirmed vulnerability and issued a pre-CVE early warning to customers.

Our warning made that uncertainty clear. Cisco had not yet published anything officially, but the report was credible enough that organisations running Cisco SD-WAN should be prepared to investigate and remediate quickly if the vulnerability was confirmed.

That confirmation has now arrived.

## What is CVE-2026-76504?

[CVE-2026-76504](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com) is an authentication bypass vulnerability in the API session-based authentication handling of Cisco Catalyst SD-WAN Manager.

According to [Cisco's security advisory for CVE-2026-76504](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com), the vulnerability is caused by improper handling of URI encoding in HTTP requests.

By sending a specially crafted request to the API, an unauthenticated remote attacker can bypass an authentication rule protecting a specific endpoint and obtain access with **admin-user privileges**.

The vulnerability is particularly serious because exploitation requires:

- **Network access:** Remote
- **Attack complexity:** Low
- **Privileges required:** None
- **User interaction:** None
- **Confidentiality impact:** High
- **Integrity impact:** High
- **Availability impact:** High
- **CVSS v3.1:** **9.8 Critical**

The full CVSS vector is:

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

Cisco states that affected Catalyst SD-WAN Manager installations are vulnerable regardless of their configuration.

## Cisco confirms active exploitation

This is not simply a theoretically exploitable vulnerability.

In its [CVE-2026-76504 advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com), Cisco PSIRT says it became aware of **active exploitation during September 2026**.

Cisco discovered the vulnerability while investigating a Cisco Technical Assistance Center support case.

Our initial early warning was based on a credible but unconfirmed pre-disclosure signal. Once Cisco published its advisory and explicitly confirmed active exploitation, the evidence moved from an early signal to authoritative vendor confirmation.

The [Previdian CVE-2026-76504 timeline](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com) tracks this progression and subsequent exploitation evidence.

## How the authentication bypass works

The vulnerability centres on the way Catalyst SD-WAN Manager processes URI-encoded characters when applying authentication rules.

Cisco's indicators demonstrate the issue using the `j_security_check` authentication endpoint.

A normal request might reference:

```
/j_security_check
```

An attacker can instead encode a character within the path. Cisco provides the following example:

```
/%6a_security_check
```

Here, `%6a` represents the letter `j`.

This encoding can result in the request bypassing an authentication rule that should otherwise restrict access to the API endpoint.

Successful exploitation can provide the remote attacker with API access using administrator privileges.

Importantly, [Cisco warns](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com) that `%6a` is only an example. **Any single encoded character may be sufficient to exploit the vulnerability.**

Defenders therefore should not build detections solely around the literal `/%6a_security_check` string.

## Indicators of compromise for CVE-2026-76504

Cisco has provided several useful indicators and hunting opportunities for organisations investigating possible exploitation of [CVE-2026-76504](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com).

### Check `serviceproxy-access.log`

Cisco recommends examining:

```
/var/log/nms/containers/service-proxy/serviceproxy-access.log
```

Look for requests involving `j_security_check` where one or more characters within the request path have been URI encoded, particularly when the requests originate from unknown or unauthorised IP addresses.

Cisco's example includes:

```
POST /%6a_security_check
```

However, searches should **not be limited to `%6a`**. Other encoded characters may also be capable of triggering the authentication bypass.

### Check `vmanage-server.log`

Cisco also recommends reviewing:

```
/var/log/nms/vmanage-server.log
```

Investigators should look for calls to `j_security_check`, including encoded variations of the path, associated with users whose names begin with:

```
viptela-reserved-
```

These are system service accounts used by Catalyst SD-WAN Manager.

Their presence alone does **not** prove exploitation. Cisco recommends comparing these events against expected network behaviour and legitimate administrative activity.

## Hunting for exploitation

As a starting point, defenders should search historical logs for:

```
j_security_check
```

and identify requests where characters in the endpoint have been URI encoded.

Do not restrict detection to:

```
/%6a_security_check
```

Suspicious requests should then be correlated with:

- Source IP addresses
- Whether the source normally administers the SD-WAN environment
- HTTP response status
- Subsequent API requests
- Authentication activity involving `viptela-reserved-*`
- Unexpected administrative activity
- Unexpected configuration changes

Because Cisco notes that some of these indicators may occur during legitimate operations, individual log entries should be treated as **hunting indicators rather than standalone evidence of compromise**.

Cisco's full investigation guidance and indicators are available in the [Cisco Catalyst SD-WAN Manager security advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com).

## Affected and fixed Cisco SD-WAN releases

Cisco has released updates addressing CVE-2026-76504 and states that **there are no workarounds that fully address the vulnerability**.

According to [Cisco's remediation guidance](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com), the relevant fixed releases are:

| Cisco Catalyst SD-WAN release | First fixed release                  |
| ----------------------------- | ------------------------------------ |
| Earlier than 20.9             | Migrate to a supported fixed release |
| 20.9                          | **20.9.10.1**                        |
| 20.12                         | **20.12.8.2**                        |
| 20.15                         | **20.15.6.1**                        |
| 20.18                         | **20.18.4.1**                        |
| 26.1                          | **26.1.2.1**                         |
| 26.2                          | **26.2.1**                           |

Cisco has also addressed the vulnerability in its managed Cisco SD-WAN Cloud service. Customers using the Cisco-managed cloud service should refer to Cisco's advisory for the applicable release and required actions.

## Internet-exposed SD-WAN Manager systems should be investigated

Cisco specifically warns about Catalyst SD-WAN Manager systems with ports exposed to the public internet.

For on-premises deployments, Cisco recommends restricting access from untrusted networks and allowing management access only from known, trusted hosts.

Cisco also recommends placing SD-WAN control components behind filtering devices such as firewalls.

These measures should **not** be considered substitutes for patching. Given the confirmed exploitation of [CVE-2026-76504](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com), organisations running affected versions should prioritise remediation.

Defenders should:

1. **Identify Catalyst SD-WAN Manager deployments and determine whether their management interfaces are internet accessible.**
2. **Upgrade to an appropriate fixed Cisco release as quickly as operationally possible.**
3. **Review historical `serviceproxy-access.log` and `vmanage-server.log` data for suspicious encoded `j_security_check` requests.**
4. **Investigate unexpected activity involving `viptela-reserved-*` accounts.**
5. **Correlate suspicious requests with subsequent administrative API activity or configuration changes.**
6. **Restrict management access to trusted hosts while remediation is underway.**

Cisco advises customers that suspect compromise to contact Cisco TAC and generate an `admin-tech` file using:

```
request admin-tech
```

The resulting information can then be provided to Cisco for further analysis.

## From rumour to confirmed exploitation

[CVE-2026-76504](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com) is a useful example of why vulnerability intelligence sometimes begins before a CVE or vendor advisory exists.

The sequence on 30 September was straightforward:

**Early warning:** A credible but unconfirmed report suggested that a serious Cisco SD-WAN vulnerability was about to be disclosed.

**Pre-disclosure:** Previdian warned customers that something potentially significant was developing while explicitly identifying the information as unconfirmed.

**Vendor disclosure:** Cisco published [its security advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com), assigning the issue **CVE-2026-76504** and a **CVSS score of 9.8**.

**Exploitation confirmation:** Cisco PSIRT confirmed that it had observed evidence of active exploitation during September 2026.

The important part of early warning is not treating every rumour as fact.

It is identifying credible signals early enough that defenders can prepare, while maintaining a clear distinction between **unconfirmed intelligence, an official vulnerability disclosure, and authoritative evidence of exploitation**.

In this case, the initial report ultimately became a **CVSS 9.8 unauthenticated authentication bypass capable of providing administrator-level API access, with Cisco confirming that exploitation has already occurred in the wild**.

## Track CVE-2026-76504

Previdian is continuing to monitor [CVE-2026-76504](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com) for new exploitation evidence, attacker activity, public exploit tooling, scanner coverage and additional defensive artifacts.

At the time of writing, Previdian has not recorded first-party sensor observations for this vulnerability. The exploitation assessment is therefore based on authoritative and corroborating evidence, led by Cisco PSIRT's confirmation of active exploitation.

You can follow the latest exploitation status, evidence and timeline on the [**Previdian CVE-2026-76504 vulnerability page**](https://previdian.com/CVE-2026-76504?utm%5Fsource=chatgpt.com).

For remediation, affected versions and Cisco's latest indicators, refer to the [**official Cisco CVE-2026-76504 security advisory**](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?utm%5Fsource=chatgpt.com).