Cisco has warned of active exploitation of CVE-2026-76504 — a CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager.
The mechanic is simple: hex-encode a character in the URI (%6a instead of j), and the authentication rule for j_security_check doesn't match. Request reaches the protected API endpoint. Admin access granted. No credentials required.
What an attacker can do with SD-WAN Manager access:
- Manipulate network fabric configuration across every branch
- Reroute or intercept traffic
- Push malicious configs to connected infrastructure
- Move laterally via SD-WAN Manager's trusted position
Key facts:
- CVSS 9.8 — AV:N/AC:L/PR:N/UI:N
- CWE-288 (Auth Bypass Using Alternate Path)
- No workarounds — patch is the only fix
- Cisco has warned of active exploitation
If you run SD-WAN Manager on-prem, check your logs before patching:
serviceproxy-access.log — look for:
vmanage-server.log — look for:
Run request admin-tech on each control component to preserve forensic evidence before upgrading.
Full breakdown with IOCs and mitigation checklist:
https://threataft.com/articles/cisco-catalyst-sd-wan-manager-cve-2026-76504-authentication-bypass
Top comments (0)