Cisco has published fixes for CVE-2026-76504, a critical zero-day in Cisco Catalyst SD-WAN Manager that is under active exploitation and permits an unauthenticated remote actor to obtain admin-level API access. The flaw impacts every deployment and CISA has placed it in its Known Exploited Vulnerabilities Catalog with a remediation deadline of Saturday, October 3. It marks the fifth SD-WAN flaw reported as exploited in the wild since the start of the year.
How the flaw enables admin access
The weakness resides in API session-based authentication management in Cisco Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. That manager is centralized software for observing and operating up to 6,000 SD-WAN devices through one console.
Cisco PSIRT said it learned of live abuse in September 2026 and announced the issue on Wednesday, urging migration to a corrected release. According to Cisco, faulty processing of URI encoding in an HTTP request makes it possible to evade an authentication check that was meant to protect one API endpoint. Practical abuse requires delivery of a specially shaped HTTP request to the API on a susceptible instance, after which the requester receives the rights of the admin user.
No additional specifics about the observed operations were disclosed. For technical details see the Cisco security advisory and the NVD entry.
Attack indicator and log review
Cisco published compromise markers centered on encoded requests. Operators were told that hostile requests employ %6a as the URI-encoded form of the character j.
Review teams examining a possibly affected manager were directed to inspect serviceproxy-access.log located under /var/log/nms/containers/service-proxy and vmanage-server.log under /var/log/nms/ for records involving j_security_check arriving from unfamiliar or unapproved IP addresses.
Illustrative review workflow, using only the supplied locations and strings:
grep -R "j_security_check" /var/log/nms/
grep -R "%6a" /var/log/nms/containers/service-proxy
Any match should be correlated against inventory of authorized sources, timestamps, and subsequent administrative actions. Cisco also asked administrators to gather admin-tech files before requesting assistance, and said customers seeking a compromise determination may open a case with the Cisco TAC.
Public notes on this CVE, including EPSS Score 0.01575 (Percentile: 0.74572) and CISA KEV addition on 2026-09-30, are summarized in PoC notes. A separate Proof-of-concept repository is referenced there.
Mitigation
Cisco states that every deployment is susceptible irrespective of system configuration. The vendor guidance is to move to a fixed software release to remediate this vulnerability.
Federal civilian agencies were ordered by CISA to address CVE-2026-76504 by Saturday, October 3, following its inclusion in the KEV Catalog. Details are in the CISA KEV alert and the KEV listing, which describes it as Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability.
Fifth exploited SD-WAN flaw this year
CVE-2026-76504 is the fifth SD-WAN zero-day described as actively exploited since the start of the year.
Earlier items in the sequence were an SD-WAN Manager information disclosure issue CVE-2026-20127 patched in February and abused since at least 2023, plus a maximum-severity Catalyst SD-WAN Controller authentication bypass CVE-2026-20182 flagged in May as exploited to secure admin rights on unpatched equipment. In early June Cisco disclosed two further SD-WAN zero-days, CVE-2026-20245 and CVE-2026-20262, exploited to obtain root rights.
Since November 2021, CISA has designated 90 Cisco vulnerabilities as exploited in the wild, with four in Cisco Catalyst SD-WAN Manager and seven misused by ransomware operations.
Technical background
This section describes the general class in generic terms and does not attribute additional specifics to this incident.
Authentication bypasses through encoding abuse happen when a front-end check compares a raw request-target string while a back-end parser normalizes it differently. An attacker supplies alternate encodings for sensitive path segments, passes the first filter, then reaches a privileged handler after decoding.
Defenders commonly look for mixed encoded and decoded variants of protected endpoint names, unexpected access to restricted APIs from external addresses, and creation or use of highly privileged sessions outside change windows. A generic illustration of the pattern, not the exploit for this CVE:
# generic example only - show how encoding can change appearance
printf '%s\n' 'j_security_check' | od -An -tx1
grep -R -i "j_security_check\|%6a" /var/log/example/