One encoded character can cross the API authentication boundary

Cisco disclosed CVE-2026-76504 on 30 September and says its Product Security Incident Response Team became aware of active exploitation during September. The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration and carries a CVSS 3.1 score of 9.8.

The product handles URI encoding incorrectly in an HTTP request. A crafted request can bypass the rule protecting a specific API endpoint and give an unauthenticated remote attacker API access with the privileges of the admin user.

Patch is the repair

Cisco says there is no workaround. Restricting management access reduces exposure, but it does not remove the vulnerable code or close the possibility that an already-reachable system was compromised before the restriction.

Map every manager to the correct destination release

Installed releaseFirst fixed releaseRequired decision
Earlier than 20.9Migrate to a fixed releaseTreat the upgrade path as a platform migration and protect the manager while it is prepared.
20.920.9.10.1Upgrade and verify the running version.
20.1220.12.8.2Upgrade and verify the running version.
20.1520.15.6.1Upgrade and verify the running version.
20.1820.18.4.1Upgrade and verify the running version.
26.126.1.2.1Upgrade and verify the running version.
26.226.2.1Upgrade and verify the running version.

Cisco says its cloud-managed SD-WAN service was fixed in release 20.15.605 and requires no customer action. Cloud customers should still record the provider-managed remediation in their vulnerability evidence.

Search for the behavior, not only Cisco’s example encoding

Cisco’s example shows %6a representing the letter j in a request to j_security_check. The advisory warns that an attacker can encode any one character, so a hunt limited to that exact string will miss equivalent requests.

  • Review /var/log/nms/containers/service-proxy/serviceproxy-access.log for requests related to j_security_check from unknown or unauthorised addresses, including percent-encoded variants.
  • Review /var/log/nms/vmanage-server.log for the same endpoint and for users whose names begin with viptela-reserved-.
  • Correlate successful responses with new sessions, configuration changes, administrator actions, software uploads, credential use, and outbound connections.
  • Compare source addresses and request timing with legitimate automation, monitoring, and administrator activity before declaring an incident.
  • Preserve manager, firewall, proxy, identity, and external log evidence; do not rely solely on files stored on the potentially compromised manager.

Treat admin-level API access as a network-control compromise

  1. 1

    Find every SD-WAN Manager. Inventory on-premises, lab, disaster-recovery, and externally hosted managers. Record software release, exposure, owner, and logging status.

  2. 2

    Reduce reachable management surface. Remove internet exposure where possible. Otherwise allow only known trusted sources through filtering controls while the fixed release is deployed.

  3. 3

    Collect evidence before disruptive changes. Export logs and generate the Cisco admin-tech bundle. Preserve the timeline before restarting, upgrading, or rebuilding the manager.

  4. 4

    Upgrade to Cisco’s fixed release. Follow the compatibility and upgrade matrices, then confirm the active version on every node rather than closing the task when the package is uploaded.

  5. 5

    Recover trust if exploitation is plausible. Review administrator identities, local and service credentials, certificates, device configuration, controller relationships, and downstream network changes. Rotate or rebuild where integrity cannot be established.

Normalise requests before matching authentication-bypass detections

The same defensive lesson seen in other encoded-path bypasses applies here: a gateway and its origin can interpret a URL differently. Detection and access controls should evaluate the normalised request that the application will process, while retaining the original request for investigation.

Cisco recommends opening a TAC case when compromise is suspected and generating an admin-tech file with the request admin-tech command for review. That vendor workflow should complement—not replace—the organisation’s wider incident response.