we_are_coded.by CODE · The world, decoded
БГ
Cisco

A 9.8 hole in Cisco SD-WAN Manager gives admin access without a password, and it is already in use

Cisco Security Advisory · event date: 30 September 2026Security

On 30 September Cisco published an advisory for CVE-2026-76504 in Catalyst SD-WAN Manager. Improper handling of URI encoding lets a remote attacker bypass the check and reach the API as admin. There is no workaround, exploitation is active, and CISA set a deadline of 3 October.

In short
  • Every configuration of Catalyst SD-WAN Manager is affected. The Cisco-managed cloud version is patched.
  • Cisco PSIRT became aware of active exploitation in September 2026.
  • Cisco gives example log lines to look for as traces of the attack.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

One letter. In Cisco's example it is j, written as %6a.

The authentication rule protects a specific address in the API. Send the same address with one encoded letter, and the rule does not recognise it but the server does. The attacker walks through the gap and comes in with admin rights.

The facts: on 30 September 2026 Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU for CVE-2026-76504 in Cisco Catalyst SD-WAN Manager, CVSS 9.8, severity Critical. Improper handling of URI encoding in an HTTP request lets an unauthenticated remote attacker bypass an authentication rule and access the API with the privileges of the admin user. Every configuration is affected; there is no workaround, and as a mitigation Cisco advises restricting access to the system from untrusted networks. In September 2026 Cisco PSIRT became aware of active exploitation. First fixed releases: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; releases earlier than 20.9 should migrate to a fixed one. The Cisco-managed cloud version is fixed in 20.15.605 with no customer action needed. Cisco lists indicators of compromise in serviceproxy-access.log and vmanage-server.log related to j_security_check. The flaw was found while resolving a Cisco technical support case. CISA added it to the Known Exploited Vulnerabilities catalogue on 30 September with a deadline of 3 October.

SD-WAN Manager is where the network between a company's branches is run from. Admin there is not access to one machine. It is access to the rules that everything else moves by.

One encoded letter, and you are admin of the network between the branches.

If you run your own installation, first cut management access from the internet, then update to the first fixed release for your branch. After that, open serviceproxy-access.log and look for j_security_check from unknown addresses. Cisco has given example lines, but warns that some of them may come from normal operation.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Cisco Security Advisory - Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability, 30.09.2026→CISA - Known Exploited Vulnerabilities Catalog, CVE-2026-76504
Original: https://wearecoded.com/en/articles/cisco-sd-wan-cve-2026-76504-admin.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news