Cisco disclosed CVE-2026-76504, a critical CVSS 9.8 authentication-bypass flaw in Cisco Catalyst SD-WAN Manager that is being actively exploited. Improper handling of URI encoding in API session authentication allows an unauthenticated remote attacker to evade login controls—such as by encoding j_security_check as %6a_security_check—and gain administrative API access. An attacker could then control managed devices and potentially compromise the entire SD-WAN environment.
Cisco has issued fixed releases for supported versions and says no workaround is available; organizations should patch immediately or disconnect vulnerable instances, particularly management interfaces exposed to the internet. Defenders should restrict management access to known IP addresses, enforce firewall protections, preserve evidence, and investigate /var/log/nms/serviceproxy-access.log and /var/log/nms/vmanage-server.log for /%6a_security_check, while recognizing that the indicator can also appear in legitimate activity.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco PSIRT had been aware of active exploitation of the Cisco Catalyst SD-WAN Manager authentication-bypass flaw since an unspecified point in September 2026. Exploitation uses URI encoding manipulation to bypass API authentication and obtain administrative access.
Cisco disclosed the critical CVE-2026-76504 authentication-bypass vulnerability in Catalyst SD-WAN Manager, rated CVSS 9.8, and published fixed releases for affected software trains. Cisco stated that no workaround is available and advised affected organizations to upgrade or disconnect vulnerable instances.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcekyberturvallisuuskeskus.fi
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.