Vulnerabilities
Cisco SD-WAN Manager flaw gives admin API with no login
CVE-2026-76504 lets an attacker reach the Cisco Catalyst SD-WAN Manager API as admin with one encoded letter. Fixed builds, log checks and cleanup.
Cisco published an advisory on September 30 for CVE-2026-76504, a critical authentication bypass in Cisco Catalyst SD-WAN Manager, the product that used to be called vManage. It is rated CVSS 9.8. An attacker with no account sends one crafted HTTP request and gets API access as the built-in admin user. Cisco says every configuration is affected and there is no workaround.
The flaw was already in use before the fix. Cisco's Product Security Incident Response Team (PSIRT) learned of exploitation in September while working a Technical Assistance Center (TAC) support case, and CISA added the bug to its Known Exploited Vulnerabilities (KEV) catalog the same day, with a remediation deadline for US federal civilian agencies of Saturday, October 3. If you run an on-premises SD-WAN Manager, check its version today, and treat it as urgent if any of its ports are reachable from the internet.
Why the Manager matters
SD-WAN Manager is the management plane for a Catalyst SD-WAN fabric. Administrators use it to build device templates, push routing and security policy, and watch every edge router in the estate. A single Manager instance can run up to 6,000 SD-WAN devices.
The admin account holds the netadmin role, which Cisco describes as able to perform all operations. With that role over the API, an attacker can read and change the configuration and policy the Manager sends to every branch router it controls. For the wide area network, the Manager plays the role a domain controller plays for Windows accounts, and it deserves the same patch priority.
How it works
Like many Java web applications, SD-WAN Manager handles its login form at a path called j_security_check, the standard endpoint for form-based login in Java servlet containers. An authentication rule sits in front of the API and decides which requests have to come from an authenticated session.
The rule does not handle URI encoding properly. In a URL, any character can be written as a percent sign and its hexadecimal code, so %6a is the letter j. A request to POST /%6a_security_check means the same thing as /j_security_check to software that decodes the path, but it does not match the rule's literal check, and the request reaches the API with admin privileges. Cisco classes this as CWE-177, improper handling of URL encoding.
Horizon3.ai notes that %6a is only one example and other encoded characters trigger the same bypass. Cisco has not said which internal component decodes the path and which one checks it. The general shape, where two parts of a request pipeline read the same path differently, is a long-standing source of authentication bypasses in web servers and proxies.
What attackers are doing
Public detail is thin. Cisco confirms active exploitation and the KEV listing confirms it independently. Neither Cisco nor CISA has named an attacker, given a start date beyond "September 2026" or said how many systems were hit. CISA lists ransomware use as unknown. No public source we found gives a count of exposed Managers.
This is not the first Cisco SD-WAN authentication flaw of the year. CVE-2026-20127 and CVE-2026-20182 were fixed earlier in 2026, and a Manager patched for those is still vulnerable to this one: the fixed builds below are new as of September 30.
What to do
1. Upgrade to a fixed release
Run show version on the Manager CLI and compare it with Cisco's first fixed releases:
| Release train | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
Upgrade every Manager in a cluster. Managers hosted by Cisco in the cloud are already on release 20.15.605, which contains the fix, so those customers have nothing to install. If your release train is not in the table, ask Cisco TAC which fixed release to move to rather than assuming yours is unaffected.
2. If you cannot upgrade today
Cisco says no workaround addresses the flaw. What it does recommend is cutting exposure: take the Manager's web and API interfaces off the internet and put a firewall or access control list in front of it that allows HTTPS only from known management hosts. That narrows who can send the crafted request. Anyone on an allowed network can still exploit the bug, so this buys time and does not replace the upgrade.
3. Check whether you were hit
Cisco points to two log files on the Manager. Reach them from the CLI with vshell, then search:
grep -E '%[0-9A-Fa-f]{2}_security_check' /var/log/nms/containers/service-proxy/serviceproxy-access.log
grep 'viptela-reserved-' /var/log/nms/vmanage-server.log
In the service proxy access log, any request to the login path with an encoded character, such as POST /%6a_security_check HTTP/1.1 returning 200, is a sign of an exploitation attempt; legitimate browsers send the plain j_security_check. Also review plain j_security_check requests from IP addresses that are not your administrators.
In vmanage-server.log, look for activity by usernames starting with viptela-reserved-. These are reserved names for internal system service accounts (Viptela was the company whose SD-WAN technology Cisco acquired), and Cisco lists their appearance in requests as an indicator that the bypass was triggered. Keep in mind an attacker with admin rights may have changed logs, so also check firewall or load balancer records of connections to the Manager from unexpected addresses.
4. If you find signs of compromise
Copy the two logs off the Manager and open a case with Cisco TAC before changing anything, so the evidence is kept. Then review what the attacker could have changed: device and feature templates, centralized and localized policies, and local user accounts on the Manager. Compare them with a known good configuration export and look for new admin users or new API tokens.
Rotate the Manager's admin and local user passwords, and any credentials the Manager stores for integrations, such as RADIUS, TACACS+ or single sign-on settings. Cisco's general hardening advice in the advisory applies here too: change default administrator passwords and create role-based accounts instead of sharing admin.
The wider lesson
SD-WAN Manager has now needed fixes for at least three authentication flaws in 2026, and each time the Managers reachable from the internet carry most of the risk. A management plane that controls thousands of routers does not need to be reachable from the internet; putting it behind a VPN or an allow list of admin hosts removes most of the exposure to the next bug of this kind as well as this one.
Our network penetration tests check which management interfaces, SD-WAN controllers included, can be reached from the internet and from user networks, and our attack surface management work keeps that list current. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Cisco security advisory cisco-sa-sdwan-webauth-xr8beuuU, CISA KEV alert, Rapid7, Horizon3.ai, Field Effect, Tech Insider, HOL, DEV Community, The Hacker News.