On 30 September Cisco published an advisory for CVE-2026-76504 in Catalyst SD-WAN Manager. Improper handling of URI encoding lets a remote attacker bypass the check and reach the API as admin. There is no workaround, exploitation is active, and CISA set a deadline of 3 October.
- Every configuration of Catalyst SD-WAN Manager is affected. The Cisco-managed cloud version is patched.
- Cisco PSIRT became aware of active exploitation in September 2026.
- Cisco gives example log lines to look for as traces of the attack.
One letter. In Cisco's example it is j, written as %6a.
The authentication rule protects a specific address in the API. Send the same address with one encoded letter, and the rule does not recognise it but the server does. The attacker walks through the gap and comes in with admin rights.
SD-WAN Manager is where the network between a company's branches is run from. Admin there is not access to one machine. It is access to the rules that everything else moves by.
If you run your own installation, first cut management access from the internet, then update to the first fixed release for your branch. After that, open serviceproxy-access.log and look for j_security_check from unknown addresses. Cisco has given example lines, but warns that some of them may come from normal operation.