# What happened Cisco reported active exploitation of a critical zero‑day in Catalyst SD‑WAN Manager (CVE‑2026‑76504) on September 30, 2026. The vulnerability is an authentication bypass in the Manager's API that allows a remote attacker to issue requests as the admin user without supplying credentials. Cisco's Product Security Incident Response Team learned of attacks while its TAC was handling a support case.
# How the flaw works The Manager mishandles URI encoding in HTTP request paths used for session login. A crafted request that encodes a single character in the login path (for example, replacing j_security_check with /%6a_security_check) can bypass an authentication restriction that was intended to limit access to a single endpoint. The attacker only needs the ability to send that request to the Manager's API. By default the admin account holds the netadmin role, which can perform all operations on the device.
# Who is affected All on‑premises Cisco Catalyst SD‑WAN Manager deployments are affected regardless of configuration. Cisco SD‑WAN Cloud (Cisco Managed) is already fixed in release 20.15.605 and requires no customer action. The advisory does not list SD‑WAN Cloud‑Pro or FedRAMP variants for this specific bulletin.
# Fixed releases (first fixed per train)
- Earlier than 20.9: migrate to a fixed release
- 20.9: 20.9.10.1
- 20.12: 20.12.8.2
- 20.15: 20.15.6.1
- 20.18: 20.18.4.1
- 26.1: 26.1.2.1
- 26.2: 26.2.1
Note: release trains such as 20.10, 20.11, 20.13, 20.14, and 20.16 are not listed in this advisory. Managers updated for earlier 2026 SD‑WAN fixes (May/June) still need this update.
# Immediate mitigations to apply
- Do not expose administrative interfaces (ports 443, 22, 830) directly to the internet.
- Place control components behind a firewall or management jump host or on a management subnet for HTTPS access.
# How to check for compromise
- Look for requests to the login path or its URI‑encoded variants (j_security_check, /%6a_security_check, or any other single‑character encoded variant).
- These entries can appear in normal traffic. Compare matches to normal activity to avoid false positives.
- If compromise is suspected, open a Severity 3 case with Cisco TAC and include CVE‑2026‑76504 in the title. Run request admin-tech on the Manager first and provide the output for TAC review.
# Important operational notes
- Cisco's advisory provides no workaround and no detection signatures. Fixed releases exist, but the advisory does not explicitly state whether upgrading ejects an attacker who already has access. Earlier Cisco advisories for other 2026 SD‑WAN flaws warned that updates alone might not resolve a confirmed compromise and instructed customers to collect admin‑tech output before upgrading.
# Action checklist for operators
- Block or restrict external access immediately and allow only trusted hosts or a jump host to reach the Manager.
- Plan and deploy the appropriate fixed release for your train as soon as possible.
- Search logs for URI‑encoded login path requests and gather admin‑tech output if suspicious activity appears. Open a Severity 3 TAC case with Cisco if you suspect compromise.