RC RANDOM CHAOS

Cisco SD WAN Flaw Under Exploit

CISA added CVE-2026-76504, an actively exploited Cisco Catalyst SD-WAN Manager auth bypass, to its KEV catalog.

· 3 min read
Cisco SD WAN Flaw Under Exploit

Cisco says attackers exploiting CVE-2026-76504 are using %6a, the URI-encoded form of j, in malicious requests against Catalyst SD-WAN Manager.

The flaw is a critical authentication bypass in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage. Cisco released fixes after its PSIRT became aware of active exploitation in September 2026. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave Federal Civilian Executive Branch agencies until October 3, 2026, to apply fixes.

The bug has a CVSS score of 9.8. The useful part for attackers is simple: an unauthenticated remote request can reach an affected system with admin privileges. Cisco described the issue as improper handling of URI encoding in an HTTP request. That handling flaw lets a crafted request bypass an authentication rule intended to restrict access to a specific API endpoint.

For a management plane, that is the part that matters. Catalyst SD-WAN Manager is the dashboard used to monitor and manage SD-WAN devices at scale, up to 6,000 devices from one place according to Cisco’s product description cited in the reporting. An API authentication bypass on that system is an access problem at the control layer, not just another web bug on an isolated appliance.

Cisco has not provided details on the exploitation activity, the actor behind it, the number of compromised organizations, or the first known exploitation date. The available public guidance is focused on patching and hunting.

The indicator Cisco called out is URL encoding around /j_security_check. Security teams should review serviceproxy-access.log under /var/log/nms/containers/service-proxy/ for entries related to j_security_check from unknown or unauthorized IP addresses. They should also review vmanage-server.log under /var/log/nms/ for the same pattern. The Hacker News report adds that defenders should look in vmanage-server.log for j_security_check calls involving users whose names start with viptela-reserved-.

Cisco also advised customers that need help determining whether a Catalyst SD-WAN Manager system was compromised to open a case with Cisco TAC, and to collect admin-tech files first to support the review.

For operators, the response should start with version inventory. The vulnerability affects all deployments regardless of system configuration, so this is not a case where a compensating configuration setting removes the exposure. Identify every Catalyst SD-WAN Manager instance, determine whether it is on a fixed release, and prioritize anything reachable from untrusted networks or broadly reachable internal zones.

The next step is log review before logs rotate away. Search for POST requests to URL-encoded variants of /j_security_check, especially requests containing %6a, and correlate hits with source IPs, user names, authentication events, and administrative activity around the same time window. Unknown or unauthorized source IPs should be treated as meaningful signals, because the exploit path is remote and unauthenticated.

There is also a larger operational pattern here. BleepingComputer counted CVE-2026-76504 as the fifth actively exploited Cisco SD-WAN zero-day reported in 2026. Earlier entries included CVE-2026-20127, CVE-2026-20182, CVE-2026-20245, and CVE-2026-20262. CISA has tagged 90 Cisco vulnerabilities as exploited in the wild since November 2021, including four in Cisco Catalyst SD-WAN Manager and seven abused by ransomware operations.

Jake Knott of watchTowr put the platform risk plainly: Cisco SD-WAN has become a recurring presence on the KEV list, and attackers have recognized the value of the platform. That tracks with the architecture. A centralized SD-WAN manager is attractive because it concentrates visibility, configuration, and control. Once that surface is reachable, authentication bugs become high-value bugs.

Apply Cisco’s fixed release, then hunt the logs Cisco named: serviceproxy-access.log and vmanage-server.log. For this vulnerability, the practical indicator is not subtle. Look for j_security_check, URL-encoded variants of that path, %6a, unknown source IPs, and unexpected viptela-reserved- user activity.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.