BREAKING: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1
Contents
Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU today (2026-09-30) for CVE-2026-76504. An unauthenticated remote attacker who can reach Cisco Catalyst SD-WAN Manager can bypass the API session auth rule with a URI-encoded request and land on the API as the admin user. Cisco rates it CVSS 3.1 base 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The bug is CWE-177 (Improper Handling of URL Encoding). There are no workarounds. The advisory says the product is affected regardless of system configuration. Cisco PSIRT became aware of active exploitation in September 2026. Fixed trains: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Cloud Hosted (Cisco Managed) is already on 20.15.605 with no customer action. This page is the operator write-up from the Cisco Security Advisory. The HOL Guard evidence pack for CVE-2026-76504 is the linked source record.
Who is not in scope
- Cisco Catalyst SD-WAN Cloud Hosted (Cisco Managed): Cisco already shipped fixed Release 20.15.605. No user action is required. Check status or version from Help in the service GUI.
- On-prem / customer-managed Managers already on a fixed build: 20.9.10.1+, 20.12.8.2+, 20.15.6.1+, 20.18.4.1+, 26.1.2.1+, or 26.2.1+ on the matching train. Releases earlier than 20.9 must migrate to a fixed release.
- Products Cisco did not list: only Cisco Catalyst SD-WAN Manager is called out as vulnerable in this advisory.
If your Manager is internet-reachable on the management plane, treat it as exposed until the build is fixed. Config flags do not carve you out: Cisco says the product is affected regardless of system configuration.
What broke
SD-WAN Manager's API session auth management mishandles URI encoding. A crafted HTTP request can skip the rule that is supposed to keep unauthenticated callers off a specific API endpoint (the advisory ties this to j_security_check). A successful exploit gives the attacker admin-user API access. Cisco Bug ID: CSCww79570. The vulnerability was found while resolving a Cisco TAC support case.
Cisco's Indicators of Compromise section shows the pattern as URI-encoding a character inside that path (example: %6a for j). Encoding any one character in the request can be enough. Treat that as an example, not the only payload shape.
What this is not
This is not a local-only misconfiguration bug, and it is not limited to Managers that enabled some optional feature. Cisco states the product is affected regardless of configuration. It is also not an RCE advisory by name: the documented impact is unauthenticated admin API access. Cisco does state active exploitation in September 2026, and there are no workarounds that fix the bug itself. Network exposure reduction is a temporary mitigation for on-prem only.
How to check
Confirm the Manager software version from the GUI Help panel or your inventory against the fixed table below. Then audit the logs Cisco names for URI-encoded j_security_check hits and viptela-reserved- system account activity from unknown IPs.
# service-proxy access log (example path from the advisory)
# /var/log/nms/containers/service-proxy/serviceproxy-access.log
# Look for URI-encoded j_security_check from unknown sources, e.g.:
# POST /%6a_security_check HTTP/1.1 200
grep -E 'j_security_check|%6[aA]_security_check|%[0-9A-Fa-f]{2}_security_check' \
/var/log/nms/containers/service-proxy/serviceproxy-access.log
# vManage server log
# /var/log/nms/vmanage-server.log
# Look for j_security_check stored for viptela-reserved- users
grep -E 'j_security_check|viptela-reserved-' /var/log/nms/vmanage-server.log
Cisco notes these IOC patterns can also appear in normal operations, so compare against your baseline. For suspected compromise, collect request admin-tech from the Manager and open a Severity 3 TAC case with CVE-2026-76504 in the title.
How to fix
Upgrade on-prem / customer-managed Cisco Catalyst SD-WAN Manager to the first fixed release on your train (or later on that train):
- Earlier than 20.9: migrate to a fixed release
- 20.9 →
20.9.10.1 - 20.12 →
20.12.8.2 - 20.15 →
20.15.6.1 - 20.18 →
20.18.4.1 - 26.1 →
26.1.2.1 - 26.2 →
26.2.1
Use the Catalyst SD-WAN Control Component Compatibility Matrix and the Cisco Catalyst SD-WAN Upgrade Matrix before you cut over. There is no software workaround. For on-prem Managers that must stay online during the window, Cisco's temporary mitigation is to keep the management plane off untrusted networks: put Control Components behind a filtering device, allow only known trusted hosts, and follow the Cisco Catalyst SD-WAN Hardening Guide. That mitigation is already deployed for Cloud Hosted environments.
References
Continue reading
All posts
Apple CoreGraphics file OOB write hits CISA KEV
How to fix CVE-2026-86950: update to iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1

BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)
How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23

Artifactory anonymous token chain hits CISA KEV
How to fix CVE-2026-42018 / CVE-2026-42016: upgrade self-hosted Artifactory past the anonymous-JWT and token-scope floors (prefer 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20)
