Cisco published an advisory on 30 September for CVE-2026-76504 (CVSS 9.8), an authentication bypass in the API session-management layer of Cisco Catalyst SD-WAN Manager that lets an unauthenticated, remote attacker send a crafted HTTP request and reach the API as the admin user. The flaw is a URI-encoding handling error: a request that encodes a single character — Cisco's example uses %6a for j — slips past an authentication rule intended to restrict one API endpoint. Cisco PSIRT says it became aware of exploitation in September 2026, and CISA added the CVE to its KEV catalogue the same day it was disclosed. There are no workarounds; fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, with earlier than 20.9 requiring migration. Cisco also published hunting guidance — audit serviceproxy-access.log for j_security_check requests from unknown addresses and vmanage-server.log for calls under accounts beginning viptela-reserved-. Cloud-hosted deployments have the mitigation applied already; on-premises operators do not.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-01 |
| Source | Cisco Security Advisory |
| Reliability | Tier 1 |
| CVEs | CVE-2026-76504 |