What happened
One encoded character can cross the API authentication boundary
Cisco disclosed CVE-2026-76504 on 30 September and says its Product Security Incident Response Team became aware of active exploitation during September. The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration and carries a CVSS 3.1 score of 9.8.
The product handles URI encoding incorrectly in an HTTP request. A crafted request can bypass the rule protecting a specific API endpoint and give an unauthenticated remote attacker API access with the privileges of the admin user.
Patch is the repair
Fixed releases
Map every manager to the correct destination release
| Installed release | First fixed release | Required decision |
|---|---|---|
| Earlier than 20.9 | Migrate to a fixed release | Treat the upgrade path as a platform migration and protect the manager while it is prepared. |
| 20.9 | 20.9.10.1 | Upgrade and verify the running version. |
| 20.12 | 20.12.8.2 | Upgrade and verify the running version. |
| 20.15 | 20.15.6.1 | Upgrade and verify the running version. |
| 20.18 | 20.18.4.1 | Upgrade and verify the running version. |
| 26.1 | 26.1.2.1 | Upgrade and verify the running version. |
| 26.2 | 26.2.1 | Upgrade and verify the running version. |
Cisco says its cloud-managed SD-WAN service was fixed in release 20.15.605 and requires no customer action. Cloud customers should still record the provider-managed remediation in their vulnerability evidence.
Hunt
Search for the behavior, not only Cisco’s example encoding
Cisco’s example shows %6a representing the letter j in a request to j_security_check. The advisory warns that an attacker can encode any one character, so a hunt limited to that exact string will miss equivalent requests.
- Review
/var/log/nms/containers/service-proxy/serviceproxy-access.logfor requests related toj_security_checkfrom unknown or unauthorised addresses, including percent-encoded variants. - Review
/var/log/nms/vmanage-server.logfor the same endpoint and for users whose names begin withviptela-reserved-. - Correlate successful responses with new sessions, configuration changes, administrator actions, software uploads, credential use, and outbound connections.
- Compare source addresses and request timing with legitimate automation, monitoring, and administrator activity before declaring an incident.
- Preserve manager, firewall, proxy, identity, and external log evidence; do not rely solely on files stored on the potentially compromised manager.
Response
Treat admin-level API access as a network-control compromise
- 1
Find every SD-WAN Manager. Inventory on-premises, lab, disaster-recovery, and externally hosted managers. Record software release, exposure, owner, and logging status.
- 2
Reduce reachable management surface. Remove internet exposure where possible. Otherwise allow only known trusted sources through filtering controls while the fixed release is deployed.
- 3
Collect evidence before disruptive changes. Export logs and generate the Cisco admin-tech bundle. Preserve the timeline before restarting, upgrading, or rebuilding the manager.
- 4
Upgrade to Cisco’s fixed release. Follow the compatibility and upgrade matrices, then confirm the active version on every node rather than closing the task when the package is uploaded.
- 5
Recover trust if exploitation is plausible. Review administrator identities, local and service credentials, certificates, device configuration, controller relationships, and downstream network changes. Rotate or rebuild where integrity cannot be established.
Defender note
Normalise requests before matching authentication-bypass detections
The same defensive lesson seen in other encoded-path bypasses applies here: a gateway and its origin can interpret a URL differently. Detection and access controls should evaluate the normalised request that the application will process, while retaining the original request for investigation.
Cisco recommends opening a TAC case when compromise is suspected and generating an admin-tech file with the request admin-tech command for review. That vendor workflow should complement—not replace—the organisation’s wider incident response.