Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-10-01 · updated: 2026-10-01 · tags: [cve, authentication-bypass, cisco, sd-wan, active-exploitation, kev] · confidence: high · severity: critical · affected_sectors: [global, government, technology] · au_impact: true

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to reach an affected system with the privileges of the admin user. The flaw is an improper handling of URI encoding in an HTTP request, which lets a crafted request bypass an authentication rule intended to restrict a specific API endpoint; Cisco's own example encodes a single character (j as %6a). Cisco PSIRT became aware of exploitation in September 2026, no workarounds exist, and CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 30 September 2026. Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; on-premises operators should audit serviceproxy-access.log for j_security_check requests from unknown addresses and vmanage-server.log for calls under accounts beginning viptela-reserved-.

Attribute Detail
CVE CVE-2026-76504
CVSS 9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor / product Cisco — Catalyst SD-WAN Manager
Reported 2026-09-30