Cisco SD-WAN Manager admin API bypass hits CISA KEV
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1
Contents
CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog today (2026-09-30). Cisco Catalyst SD-WAN Manager has a hex/URI-encoding bug: an unauthenticated remote attacker who can reach the Manager can bypass the API session auth rule and land on the admin API. Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU this morning, rates it CVSS 3.1 base 9.8, and says PSIRT became aware of active exploitation in September 2026. There are no workarounds. Federal KEV due date is 2026-10-03. Forensic triage is Yes under BOD 26-04. Known ransomware campaign use is Unknown.
This is the KEV follow-up to our same-day BREAKING write-up: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504). That page still has the full operator detail. This page adds the CISA KEV clock (catalogVersion 2026.09.30, dateAdded 2026-09-30) and the federal triage due date. The HOL Guard evidence pack for CVE-2026-76504 is the linked source record.
Who is not in scope
- Cisco Catalyst SD-WAN Cloud Hosted (Cisco Managed): Cisco already shipped fixed Release 20.15.605. No customer action. Confirm status from Help in the service GUI.
- On-prem / customer-managed Managers already on a fixed build: 20.9.10.1+, 20.12.8.2+, 20.15.6.1+, 20.18.4.1+, 26.1.2.1+, or 26.2.1+ on the matching train. Releases earlier than 20.9 must migrate to a fixed release.
- Products Cisco did not list: only Cisco Catalyst SD-WAN Manager is named in this advisory. Do not treat a random IOS-XE or Meraki advisory as coverage for 76504.
If your Manager is internet-reachable on the management plane, treat it as exposed until the build is fixed. Cisco says the product is affected regardless of system configuration. Config flags do not carve you out of KEV.
What breaks
SD-WAN Manager's API session auth mishandles URI encoding (CWE-177). A crafted HTTP request can skip the rule that is supposed to keep unauthenticated callers off a specific API endpoint (Cisco ties this to j_security_check). A successful exploit gives admin-user API access. Cisco Bug ID: CSCww79570. CISA's KEV short description matches: hex encoding vulnerability, unauthenticated remote attacker can access the affected system with admin privileges due to improper handling of URI encoding in an HTTP request.
Cisco's Indicators of Compromise section shows URI-encoding a character inside that path (example: %6a for j). Encoding any one character in the request can be enough. Treat that as an example, not the only payload shape. Same-day KEV means the federal clock and BOD 26-04 forensic triage apply even if you already started patching from this morning's advisory.
What this is not
This is not a local misconfiguration bug, and it is not limited to Managers that enabled some optional feature. It is also not an RCE advisory by name: the documented impact is unauthenticated admin API access. Network exposure reduction is a temporary mitigation for on-prem only, not a fix. KEV does not invent a new bug; it marks this CVE as known-exploited with a due date.
How to check
Confirm the Manager software version from the GUI Help panel or your inventory against the fixed table below. Then audit the logs Cisco names for URI-encoded j_security_check hits and viptela-reserved- system account activity from unknown IPs.
# service-proxy access log (example path from the advisory)
# /var/log/nms/containers/service-proxy/serviceproxy-access.log
# Look for URI-encoded j_security_check from unknown sources, e.g.:
# POST /%6a_security_check HTTP/1.1 200
grep -E 'j_security_check|%6[aA]_security_check|%[0-9A-Fa-f]{2}_security_check' \
/var/log/nms/containers/service-proxy/serviceproxy-access.log
# vManage server log
# /var/log/nms/vmanage-server.log
# Look for j_security_check stored for viptela-reserved- users
grep -E 'j_security_check|viptela-reserved-' /var/log/nms/vmanage-server.log
Cisco notes these IOC patterns can also appear in normal operations, so compare against your baseline. For suspected compromise, collect request admin-tech from the Manager and open a Severity 3 TAC case with CVE-2026-76504 in the title. Federal agencies under BOD 26-04 also owe forensic triage by the KEV due date.
How to fix
Upgrade on-prem / customer-managed Cisco Catalyst SD-WAN Manager to the first fixed release on your train (or later on that train):
- Earlier than 20.9: migrate to a fixed release
- 20.9 →
20.9.10.1 - 20.12 →
20.12.8.2 - 20.15 →
20.15.6.1 - 20.18 →
20.18.4.1 - 26.1 →
26.1.2.1 - 26.2 →
26.2.1
Use the Catalyst SD-WAN Control Component Compatibility Matrix and the Cisco Catalyst SD-WAN Upgrade Matrix before you cut over. There is no software workaround. For on-prem Managers that must stay online during the window, Cisco's temporary mitigation is to keep the management plane off untrusted networks: put Control Components behind a filtering device, allow only known trusted hosts, and follow the Cisco Catalyst SD-WAN Hardening Guide. That mitigation is already deployed for Cloud Hosted environments. Federal due date under this KEV row is 2026-10-03.
References
- CISA Known Exploited Vulnerabilities catalog (CVE-2026-76504, dateAdded 2026-09-30, dueDate 2026-10-03, catalogVersion 2026.09.30, BOD 26-04, forensic triage Yes, ransomware Unknown)
- Cisco Security Advisory: cisco-sa-sdwan-webauth-xr8beuuU (CVE-2026-76504)
- HOL BREAKING write-up (same-day advisory)
Continue reading
All posts
BREAKING: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1

Apple CoreGraphics file OOB write hits CISA KEV
How to fix CVE-2026-86950: update to iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1

BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)
How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23
