CVE-2026-76504: Critical Cisco Catalyst SD-WAN Manager Authentication Bypass Exploited in the Wild
Cisco has disclosed CVE-2026-76504, a critical unauthenticated authentication bypass affecting Cisco Catalyst SD-WAN Manager, formerly known as Cisco vManage.
The vulnerability carries a CVSS v3.1 score of 9.8, requires no authentication or user interaction, and can give a remote attacker API access with administrator privileges. Most importantly, Cisco has confirmed that CVE-2026-76504 is being actively exploited.
The disclosure also confirms an early warning for CVE-2026-76504 that Previdian sent to customers earlier on 30 September, before official technical details were available.
What initially appeared as an unconfirmed rumour about a serious Cisco SD-WAN vulnerability has now developed into a critical vulnerability with confirmed real-world exploitation.
The warning before the disclosure
Earlier on 30 September, a report in the Cisco community on Reddit warned that a substantial Cisco SD-WAN vulnerability was expected to be announced later that day.
At the time, there was no CVE, Cisco security advisory, technical detail, or official confirmation of exploitation.
Previdian treated the report as an early signal rather than a confirmed vulnerability and issued a pre-CVE early warning to customers.
Our warning made that uncertainty clear. Cisco had not yet published anything officially, but the report was credible enough that organisations running Cisco SD-WAN should be prepared to investigate and remediate quickly if the vulnerability was confirmed.
That confirmation has now arrived.
What is CVE-2026-76504?
CVE-2026-76504 is an authentication bypass vulnerability in the API session-based authentication handling of Cisco Catalyst SD-WAN Manager.
According to Cisco's security advisory for CVE-2026-76504, the vulnerability is caused by improper handling of URI encoding in HTTP requests.
By sending a specially crafted request to the API, an unauthenticated remote attacker can bypass an authentication rule protecting a specific endpoint and obtain access with admin-user privileges.
The vulnerability is particularly serious because exploitation requires:
- Network access: Remote
- Attack complexity: Low
- Privileges required: None
- User interaction: None
- Confidentiality impact: High
- Integrity impact: High
- Availability impact: High
- CVSS v3.1: 9.8 Critical
The full CVSS vector is:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCisco states that affected Catalyst SD-WAN Manager installations are vulnerable regardless of their configuration.
Cisco confirms active exploitation
This is not simply a theoretically exploitable vulnerability.
In its CVE-2026-76504 advisory, Cisco PSIRT says it became aware of active exploitation during September 2026.
Cisco discovered the vulnerability while investigating a Cisco Technical Assistance Center support case.
Our initial early warning was based on a credible but unconfirmed pre-disclosure signal. Once Cisco published its advisory and explicitly confirmed active exploitation, the evidence moved from an early signal to authoritative vendor confirmation.
The Previdian CVE-2026-76504 timeline tracks this progression and subsequent exploitation evidence.
How the authentication bypass works
The vulnerability centres on the way Catalyst SD-WAN Manager processes URI-encoded characters when applying authentication rules.
Cisco's indicators demonstrate the issue using the j_security_check authentication endpoint.
A normal request might reference:
/j_security_checkAn attacker can instead encode a character within the path. Cisco provides the following example:
/%6a_security_checkHere, %6a represents the letter j.
This encoding can result in the request bypassing an authentication rule that should otherwise restrict access to the API endpoint.
Successful exploitation can provide the remote attacker with API access using administrator privileges.
Importantly, Cisco warns that %6a is only an example. Any single encoded character may be sufficient to exploit the vulnerability.
Defenders therefore should not build detections solely around the literal /%6a_security_check string.
Indicators of compromise for CVE-2026-76504
Cisco has provided several useful indicators and hunting opportunities for organisations investigating possible exploitation of CVE-2026-76504.
Check serviceproxy-access.log
Cisco recommends examining:
/var/log/nms/containers/service-proxy/serviceproxy-access.logLook for requests involving j_security_check where one or more characters within the request path have been URI encoded, particularly when the requests originate from unknown or unauthorised IP addresses.
Cisco's example includes:
POST /%6a_security_checkHowever, searches should not be limited to %6a. Other encoded characters may also be capable of triggering the authentication bypass.
Check vmanage-server.log
Cisco also recommends reviewing:
/var/log/nms/vmanage-server.logInvestigators should look for calls to j_security_check, including encoded variations of the path, associated with users whose names begin with:
viptela-reserved-These are system service accounts used by Catalyst SD-WAN Manager.
Their presence alone does not prove exploitation. Cisco recommends comparing these events against expected network behaviour and legitimate administrative activity.
Hunting for exploitation
As a starting point, defenders should search historical logs for:
j_security_checkand identify requests where characters in the endpoint have been URI encoded.
Do not restrict detection to:
/%6a_security_checkSuspicious requests should then be correlated with:
- Source IP addresses
- Whether the source normally administers the SD-WAN environment
- HTTP response status
- Subsequent API requests
- Authentication activity involving
viptela-reserved-* - Unexpected administrative activity
- Unexpected configuration changes
Because Cisco notes that some of these indicators may occur during legitimate operations, individual log entries should be treated as hunting indicators rather than standalone evidence of compromise.
Cisco's full investigation guidance and indicators are available in the Cisco Catalyst SD-WAN Manager security advisory.
Affected and fixed Cisco SD-WAN releases
Cisco has released updates addressing CVE-2026-76504 and states that there are no workarounds that fully address the vulnerability.
According to Cisco's remediation guidance, the relevant fixed releases are:
| Cisco Catalyst SD-WAN release | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a supported fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Cisco has also addressed the vulnerability in its managed Cisco SD-WAN Cloud service. Customers using the Cisco-managed cloud service should refer to Cisco's advisory for the applicable release and required actions.
Internet-exposed SD-WAN Manager systems should be investigated
Cisco specifically warns about Catalyst SD-WAN Manager systems with ports exposed to the public internet.
For on-premises deployments, Cisco recommends restricting access from untrusted networks and allowing management access only from known, trusted hosts.
Cisco also recommends placing SD-WAN control components behind filtering devices such as firewalls.
These measures should not be considered substitutes for patching. Given the confirmed exploitation of CVE-2026-76504, organisations running affected versions should prioritise remediation.
Defenders should:
- Identify Catalyst SD-WAN Manager deployments and determine whether their management interfaces are internet accessible.
- Upgrade to an appropriate fixed Cisco release as quickly as operationally possible.
- Review historical
serviceproxy-access.logandvmanage-server.logdata for suspicious encodedj_security_checkrequests. - Investigate unexpected activity involving
viptela-reserved-*accounts. - Correlate suspicious requests with subsequent administrative API activity or configuration changes.
- Restrict management access to trusted hosts while remediation is underway.
Cisco advises customers that suspect compromise to contact Cisco TAC and generate an admin-tech file using:
request admin-techThe resulting information can then be provided to Cisco for further analysis.
From rumour to confirmed exploitation
CVE-2026-76504 is a useful example of why vulnerability intelligence sometimes begins before a CVE or vendor advisory exists.
The sequence on 30 September was straightforward:
Early warning: A credible but unconfirmed report suggested that a serious Cisco SD-WAN vulnerability was about to be disclosed.
Pre-disclosure: Previdian warned customers that something potentially significant was developing while explicitly identifying the information as unconfirmed.
Vendor disclosure: Cisco published its security advisory, assigning the issue CVE-2026-76504 and a CVSS score of 9.8.
Exploitation confirmation: Cisco PSIRT confirmed that it had observed evidence of active exploitation during September 2026.
The important part of early warning is not treating every rumour as fact.
It is identifying credible signals early enough that defenders can prepare, while maintaining a clear distinction between unconfirmed intelligence, an official vulnerability disclosure, and authoritative evidence of exploitation.
In this case, the initial report ultimately became a CVSS 9.8 unauthenticated authentication bypass capable of providing administrator-level API access, with Cisco confirming that exploitation has already occurred in the wild.
Track CVE-2026-76504
Previdian is continuing to monitor CVE-2026-76504 for new exploitation evidence, attacker activity, public exploit tooling, scanner coverage and additional defensive artifacts.
At the time of writing, Previdian has not recorded first-party sensor observations for this vulnerability. The exploitation assessment is therefore based on authoritative and corroborating evidence, led by Cisco PSIRT's confirmation of active exploitation.
You can follow the latest exploitation status, evidence and timeline on the Previdian CVE-2026-76504 vulnerability page.
For remediation, affected versions and Cisco's latest indicators, refer to the official Cisco CVE-2026-76504 security advisory.