Cisco Catalyst SD-WAN Manager CVE-2026-76504: Fixed Releases and Log Checks

Cisco says an unauthenticated authentication bypass in Catalyst SD-WAN Manager is being exploited. There is no workaround, only upgrades, a temporary shield and a short list of log entries worth checking today.

Fiber optic cables plugged into a network switch
Photo by Lightsaber Collection on Unsplash

If you run Cisco Catalyst SD-WAN Manager (formerly vManage) on your own infrastructure, you need to do two things today: confirm whether it is reachable from the internet, and look at two log files for requests that mention j_security_check. Cisco says the flaw, CVE-2026-76504, lets an unauthenticated attacker act as the admin user through the manager’s API, and that its security team became aware of active exploitation in September 2026. The only remediation is a software upgrade.

What Cisco has published

Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU on September 30, 2026. Version 1.1, dated October 2, 2026, added information about a temporary protection called Live Protect. Cisco rates it Critical.

CVE-2026-76504
ProductCisco Catalyst SD-WAN Manager (the management and control interface for a Cisco SD-WAN network)
WeaknessImproper handling of URI encoding (CWE-177) in API session-based authentication
Access neededNone. The attacker does not need an account
What the attacker gainsAccess to the API with the privileges of the admin user
CVSS 3.1 base score9.8 (Critical), as assigned by Cisco
Affected systemsSD-WAN Manager “regardless of system configuration”
WorkaroundNone
ExploitationCisco PSIRT became aware of active exploitation in September 2026. The advisory gives no more precise date
How it was foundDuring the resolution of a Cisco Technical Assistance Center (TAC) support case

CVSS (Common Vulnerability Scoring System) is the standard 0 to 10 severity scale; this score uses version 3.1.

Cisco describes the mechanism this way: improper handling of URI encoding in an HTTP request lets a request bypass an authentication rule meant to restrict access to a specific API endpoint. URI encoding replaces a character with a percent sign and two hexadecimal digits, so j can be written %6a. Cisco’s description implies the check looks at the encoded form while the application later treats it as the plain character. That last step is our reading of the mechanism, not a statement in the advisory.

Which releases are fixed

Cisco’s advisory gives these first fixed releases:

SD-WAN software release trainFirst fixed release
Earlier than 20.9Migrate to a fixed release
20.920.9.10.1
20.1220.12.8.2
20.1520.15.6.1
20.1820.18.4.1
26.126.1.2.1
26.226.2.1

Two points on reading this table. First, the table lists only these trains. If you run a train that is not in it, the advisory neither marks that train fixed nor says it is unaffected, and we could not find a Cisco statement on it. Treat it as unresolved and ask Cisco TAC rather than assume it is covered. Second, Cisco says it validates only the affected and fixed release information in the advisory, so use the advisory, not a scanner’s interpretation of the CVE record, to decide.

For Cisco-hosted deployments, Cisco says the flaw is addressed in SD-WAN Cloud (Cisco Managed) release 20.15.605 with no customer action needed.

The Live Protect shield: what it is and is not

Cisco’s October 2 update says it released a Live Protect shield for this CVE “to provide temporary security coverage to allow time for software upgrade planning”. Cisco is explicit about the limits: it “offers only temporary partial protection” and “the only way to remediate this vulnerability is to upgrade to the first fixed software release”. It also warns of a side effect: a legitimate user who uses URI encoding might not be able to log in to SD-WAN Manager once the shield is applied.

Our reading: use the shield, if you use it at all, to buy days while you schedule the upgrade, not as the end state. “Partial” means Cisco is not claiming it blocks every variant. Cisco’s documentation for the feature is Live Protect for Cisco Catalyst SD-WAN. We did not test the shield.

Reduce exposure first

Cisco’s mitigation for on-premises deployments is to restrict access from unsecured networks, including the internet. If you need internet access to the manager, Cisco says to restrict it to known, trusted hosts on the ports and protocols in its user guides, and to place the control components behind a filtering device such as a firewall. Cisco’s advisory says managers “exposed to the internet” with ports exposed are at risk.

Practical steps that follow from that:

  • Find out whether the manager’s web and API ports are reachable from the internet. Check from outside your network, not from the configuration alone.
  • If they are, restrict them to a management network or a named allowlist before you do anything else. This does not fix the flaw, but it removes the unauthenticated attacker’s path while you plan the upgrade.
  • Remember what the manager controls. SD-WAN Manager is the administrative plane for the WAN, so admin API access is access to the network’s configuration. That is our assessment of impact, not a Cisco statement of what an attacker did.

Check for exploitation

Cisco says its indicators may also occur during normal operations, so assess them against your usual traffic. It names two files:

  1. /var/log/nms/containers/service-proxy/serviceproxy-access.log. Look for entries related to j_security_check from unknown or unauthorized IP addresses. Cisco’s example is a POST /%6a_security_check request.
  2. /var/log/nms/vmanage-server.log. Look for entries related to j_security_check from unknown or unauthorized IP addresses, specifically for users whose names start with viptela-reserved-. Cisco’s example reads Request Stored in Map is (/%6a_security_check) for user (viptela-reserved-..).

viptela-reserved- accounts are system service accounts that Cisco documents in the authentication section of its SD-WAN configuration guide. A request that authenticates as one of them from an outside address is the pattern Cisco is pointing to.

Cisco states the %6a form is only an example: “the vulnerability will allow any one character that is encoded in the request to be used to exploit this.” So searching for %6a alone will miss other variants. As an untested starting point (ours, not Cisco’s), also list every request to the endpoint whose path contains a percent-encoded character:

grep -E 'POST /[^ ]*%[0-9A-Fa-f]{2}[^ ]*' serviceproxy-access.log

Review the results against your normal logins. Expect some noise, because other legitimate requests can contain encoded characters.

Cisco’s other guidance:

  • To determine whether a system has been compromised, open a Cisco TAC case as Severity 3 with CVE-2026-76504 in the title. Before opening it, run request admin-tech on the manager so the diagnostic file can go to TAC.
  • Cisco publishes Snort rule 67179 for this advisory, for teams that run Snort-based inspection in front of the manager.
  • Send manager logs to an external server and retain them long enough for investigations, which is also general hardening advice in the advisory. Our piece on logging for incidents rather than dashboards covers why.

Upgrade, then decide what else to rotate

Cisco’s advice is to upgrade to a fixed release as soon as possible. The advisory does not describe what an attacker with admin API access did in the observed attacks, and we found no public report that does. So the following is general incident response practice, not vendor guidance, and applies if your logs show a suspicious request:

  • Treat the manager’s configuration as readable and changeable by an outsider for the period of exposure. Review recent user, template and policy changes.
  • Rotate the administrator credentials and any API keys or integration credentials the manager holds.
  • Cisco’s hardening list also says to change the default administrator password and to restrict the administrator account by creating named user accounts based on access needs. Do both if you have not.

What the CISA entry means

CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026, the day Cisco published. The entry sets a due date of October 3, 2026, requires forensic triage, and lists ransomware campaign use as “Unknown”. CISA’s enrichment data on the CVE record rates exploitation “active”, automatable “yes” and technical impact “total”. The due date comes from Binding Operational Directive 26-04 and applies to US Federal Civilian Executive Branch agencies; it does not bind private companies.

What this adds up to

This section is editorial analysis.

CISA’s catalog added Citrix NetScaler (September 27), this Cisco flaw (September 30), Fortinet FortiMail (October 1) and Zammad (October 2) within six days. They are different products and different bugs, but each is software reachable over the network that was already being exploited when the advisory appeared. We covered the FortiMail file-write zero-day, the Citrix NetScaler zero-days and the Zammad zero-days separately. Three habits shorten the next response:

  • Keep management planes off the public internet. Cisco’s own mitigation is this. If the only thing standing between the internet and admin access is a login check, one encoding bug removes it.
  • Know your release train before the advisory arrives. The table above only helps if you can say in a minute which train you run.
  • Ship manager logs off the box. Cisco’s indicators are log lines. They are only useful if the logs exist and an intruder could not have edited them. For triage order, see what a zero-day is and how to respond to one and the vulnerability backlog that never shrinks.

Sources and verification

Checked on October 5, 2026. We did not test the vulnerability, the Live Protect shield or the grep pattern on a Cisco SD-WAN Manager. We could not open CISA’s website from our environment, so CISA data was read from CISA’s published KEV data file and from CISA’s entry embedded in the CVE record.

Important claimSourceVerification
Unauthenticated remote attacker can gain admin-level API access via URI-encoding handling flaw; affects SD-WAN Manager regardless of configurationCisco advisory cisco-sa-sdwan-webauth-xr8beuuU, first published September 30, 2026Verified
CVSS 3.1 base score 9.8; CWE-177Cisco advisory; CVE record, updated October 2, 2026Verified
Cisco PSIRT became aware of active exploitation in September 2026Cisco advisory, Exploitation and Public AnnouncementsVerified: no more precise date given
First fixed releases 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1; earlier than 20.9 migrateCisco advisory, Fixed Releases tableVerified
No fixed release is listed for trains not named in the tableCisco advisory, Fixed Releases table, as read October 5, 2026Qualified: absence of a listing, not a Cisco statement
No workaround; mitigation is restricting access from unsecured networks; already deployed for cloud-hostedCisco advisoryVerified
Cloud (Cisco Managed) release 20.15.605 addresses the flawCisco advisoryVerified
Live Protect shield added October 2, 2026; temporary, partial; may block legitimate URI-encoded loginsCisco advisory, version 1.1Verified
Log files and j_security_check / viptela-reserved- indicators; any single encoded character can be usedCisco advisory, Indicators of CompromiseVerified
TAC case at Severity 3 with CVE ID in title; run request admin-tech first; Snort rule 67179Cisco advisoryVerified
Added to CISA KEV September 30, 2026; due October 3; forensic triage required; ransomware use unknownCISA KEV data, catalog version 2026.10.04Verified
CISA rates exploitation active, automatable yes, technical impact totalCISA ADP entry in the CVE record, dated September 30, 2026Verified
BOD 26-04 binds US federal civilian agenciesTenable analysis of BOD 26-04Qualified: secondary source

Frequently asked questions

Which Cisco Catalyst SD-WAN Manager releases fix CVE-2026-76504?

Cisco's advisory lists these first fixed releases: 20.9.10.1 for the 20.9 train, 20.12.8.2 for 20.12, 20.15.6.1 for 20.15, 20.18.4.1 for 20.18, 26.1.2.1 for 26.1 and 26.2.1 for 26.2. It says releases earlier than 20.9 should migrate to a fixed release. Trains not named in the table have no fixed release listed, so ask Cisco TAC or check the advisory for updates.

Is there a workaround?

No. Cisco's advisory says there are no workarounds that address the vulnerability. For on-premises deployments it recommends as a mitigation restricting access from unsecured networks such as the internet, and allowing only known trusted hosts if internet access is required. For Cisco-hosted cloud deployments Cisco says this mitigation is already deployed.

Are Cisco-hosted SD-WAN cloud customers affected?

Cisco says it has addressed the flaw in Cisco SD-WAN Cloud (Cisco Managed) release 20.15.605 and that no customer action is required. You can check your remediation status and version through the Help function in the service GUI.

Does the CISA deadline apply to private companies?

No. CISA's catalog entry sets October 3, 2026 under Binding Operational Directive 26-04, which applies to US Federal Civilian Executive Branch agencies. Other organizations are not bound by it, but the three-day window signals urgency.

Vulnerability ManagementIncident Response