FR
live
Security Critical

Cisco patches an authentication zero-day in Catalyst SD-WAN Manager already exploited in the wild

CVE-2026-76504 lets an unauthenticated attacker bypass Catalyst SD-WAN Manager authentication through URI encoding and gain admin rights. There is no workaround: patch immediately and inspect j_security_check logs.

A row of identical server cabinets in a dark hall, one single door left ajar leaking a thin amber light.

September 30, 2026. Cisco ships a fix for a critical flaw in Catalyst SD-WAN Manager, the former SD-WAN vManage, and confirms it is already exploited in the wild. September 30, 2026. CISA adds CVE-2026-76504 to its KEV catalog with a federal deadline of October 3. September 30, 2026. The vendor reveals attackers are using the %6a character in their malicious requests. Why it matters: this is the fifth SD-WAN zero-day exploited since January, and this one has no workaround — only the patch counts.

Authentication bypassed through URI encoding

The mechanism fits in one sentence. CVE-2026-76504 stems from improper handling of URI encoding in an HTTP request: by encoding a character, an attacker slides a request past an authentication rule that is meant to protect a specific API endpoint.

The result is blunt. Cisco describes an authentication bypass in the API’s session-based authentication management, reachable with no prior authentication: a single crafted HTTP request is enough to access the system remotely with admin or netadmin privileges. The CVSS 9.8 score reflects the combination of network reachability, no prerequisites, and complete impact on confidentiality, integrity and availability.

The marker Cisco shared confirms the mechanism. The targeted endpoint is j_security_check, the application layer’s authentication path: by encoding the “j” as %6a, the request no longer matches the string the rule watches, and passes as an already-authenticated user. It is the same principle as a filter that compares a literal string without decoding the URI first — a class of mistake that keeps recurring in exposed web consoles.

Urgency scales with exposure. BleepingComputer flags internet-reachable Managers as the highest-risk targets, since a single crafted request can land admin rights with no credential. A console that sits behind a VPN or internal segmentation is still vulnerable to the same request from any compromised host, but the patch window is more forgiving.

The affected product is not an edge router but the console that drives it. Catalyst SD-WAN Manager administers up to 6,000 SD-WAN devices from a single dashboard. Compromising the manager means inheriting the trust of the entire fleet it supervises — a pivot point far more dangerous than an isolated router.

The fifth SD-WAN flaw exploited in 2026

This zero-day is not an isolated accident; it is a trend. Cisco has already patched four SD-WAN flaws exploited in the wild since the start of the year.

  • February. CVE-2026-20127, an information disclosure in SD-WAN Manager, exploited as a zero-day since at least 2023.
  • May. CVE-2026-20182, a maximum-severity authentication bypass on Catalyst SD-WAN Controller, exploited to gain admin rights.
  • June. CVE-2026-20245 and CVE-2026-20262, two more zero-days exploited to reach root on vulnerable systems.

CISA’s arithmetic drives the point home: since November 2021 the agency has tagged 90 Cisco vulnerabilities as exploited, including four in Catalyst SD-WAN Manager alone and seven abused by ransomware operations.

The message is simple. Edge appliances and their management consoles have become the favorite target of malicious actors, because they are internet-exposed, slow to patch, and they open onto an entire network. An internet-reachable SD-WAN Manager console is a password in itself: leaving it unpatched means leaving the key in the lock.

Catalyst SD-WAN Manager illustrates a problem larger than this one product. Network management consoles combine three structural weaknesses: they are internet-exposed by operational necessity, they patch slowly because a maintenance window affects the whole fleet they supervise, and they concentrate elevated privileges that make them a high-yield target.

The consequence shows in CISA’s numbers. Of the 90 Cisco vulnerabilities tagged in the KEV since November 2021, a disproportionate share hits precisely these edge appliances and their consoles — routers, firewalls, SD-WAN controllers. It is not the most numerous products that get targeted, but the ones that open the widest door.

The operational lesson is old but rarely applied: a management console has no business being reachable from the internet. When it must be, it deserves the same discipline as a critical asset — strong authentication, segmentation, log monitoring and patching within 24 to 48 hours for exploited flaws.

Detecting a compromise already under way

The patch is not enough: you must determine whether the system has already been visited. Cisco provides precise indicators of compromise, which is rare and valuable.

First, the technical marker. Attackers use %6a — the URI-encoded character “j” — in their malicious requests. Any request carrying this pattern toward the authentication endpoint deserves immediate scrutiny.

Second, the logs to search. Two files concentrate the suspicious activity:

bash
# Requests to the service proxy (look for anomalous j_security_check entries)
grep 'j_security_check' /var/log/nms/containers/service-proxy/serviceproxy-access.log

# Main manager log
grep 'j_security_check' /var/log/nms/vmanage-server.log

The operational guidance fits in one sentence: look for j_security_check entries originating from unknown or unauthorized IP addresses. Such an entry is a compromise signal, not a false positive to ignore. For uncertain cases, Cisco invites customers to collect admin-tech files and open a case with the TAC.

The fixed-version table leaves no ambiguity. 20.9 moves to 20.9.10.1, 20.12 to 20.12.8.2, 20.15 to 20.15.6.1, 20.18 to 20.18.4.1, 26.1 to 26.1.2.1, and 26.2 to 26.2.1. Deployments earlier than 20.9 must migrate to a fixed release — there is no documented workaround.

The remediation plan breaks down into four steps, in this order.

  • 1. Cut exposure. Remove the console from direct internet access, or put it behind a VPN and strict segmentation while applying the patch.
  • 2. Apply the patch. Move to the fixed release of the relevant branch — 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1.
  • 3. Hunt for traces. Grep the j_security_check logs and the %6a pattern for any unknown address.
  • 4. If compromised, pivot. Rotate credentials, inventory supervised devices and review recent configuration changes.

Verdict

If your Catalyst SD-WAN Manager is internet-exposed, the patch is an urgency on the same footing as a confirmed breach: with no workaround, every hour of exposure is an hour of risk, and CISA expects remediation by October 3. If the exposure is internal but the console supervises a sensitive fleet, treat the fix as a priority anyway, because lateral movement from a compromised workstation would land at the same point. In every case, before patching, grep the j_security_check logs: a console that has already been visited demands credential rotation and an inventory of supervised devices, not just an update.

References

cve

Linked vulnerabilities

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Apple patches a CoreGraphics zero-day exploited against targeted individuals

An out-of-bounds write in CoreGraphics allows code execution when a crafted file is opened, and CISA added it to the KEV catalog after confirmed exploitation. Roll out iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1 or macOS Tahoe 26.7.1 immediately, starting with the devices of exposed people.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss