Cisco SD-WAN Manager auth bypass exploited in wild
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Attackers exploit CVE-2026-76504, a URI-encoding flaw in Cisco Catalyst SD-WAN Manager, to gain unauthenticated admin API access.
Cisco Catalyst SD-WAN Manager (formerly vManage) contains an authentication bypass vulnerability, CVE-2026-76504, that Cisco's PSIRT confirms is being actively exploited in the wild as of September 2026. The flaw stems from improper handling of URI-encoded characters in HTTP requests to the API's login-handler path (j_security_check). By URI-encoding a character (Cisco's IOC points to encoding the letter 'j'), an attacker can cause the authentication rule guarding a specific endpoint to fail to match, allowing the request through without credentials and granting admin-level API access.
Because SD-WAN Manager is the centralized console for managing SD-WAN fabric devices—sometimes thousands from a single instance—successful exploitation gives an unauthenticated remote attacker full administrative control over the API, enabling viewing or modification of configuration on every managed device, account creation, or program installation. The vulnerability affects the product regardless of configuration; there is no toggle or workaround to remove the exposure. Affected versions span multiple release trains prior to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1.
Defenders should treat patching as an emergency, out-of-cycle deployment given the lack of workaround, restrict management-plane/API access to trusted networks, and review authentication/API logs for requests to the j_security_check path containing URI-encoded characters. Forensic evidence should be preserved on any exposed instance prior to upgrading.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-cisco-catalyst-sd-wan-manager-could-allow-for-authentication-bypass_2026-105
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,484 reports from 153 sources, 493 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs