# Cisco SD-WAN Manager auth bypass exploited in wild

Published: 2026-09-30 · Severity: severe · Sectors: government-national, telecommunications, technology
Canonical: https://vorant.io/reports/c086c6e7-dd42-5afe-a590-09e2f3e9822b/cisco-sd-wan-manager-auth-bypass-exploited-in-wild

> Attackers exploit CVE-2026-76504, a URI-encoding flaw in Cisco Catalyst SD-WAN Manager, to gain unauthenticated admin API access.

Cisco Catalyst SD-WAN Manager (formerly vManage) contains an authentication bypass vulnerability, CVE-2026-76504, that Cisco's PSIRT confirms is being actively exploited in the wild as of September 2026. The flaw stems from improper handling of URI-encoded characters in HTTP requests to the API's login-handler path (j_security_check). By URI-encoding a character (Cisco's IOC points to encoding the letter 'j'), an attacker can cause the authentication rule guarding a specific endpoint to fail to match, allowing the request through without credentials and granting admin-level API access.

Because SD-WAN Manager is the centralized console for managing SD-WAN fabric devices—sometimes thousands from a single instance—successful exploitation gives an unauthenticated remote attacker full administrative control over the API, enabling viewing or modification of configuration on every managed device, account creation, or program installation. The vulnerability affects the product regardless of configuration; there is no toggle or workaround to remove the exposure. Affected versions span multiple release trains prior to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1.

Defenders should treat patching as an emergency, out-of-cycle deployment given the lack of workaround, restrict management-plane/API access to trusted networks, and review authentication/API logs for requests to the j_security_check path containing URI-encoded characters. Forensic evidence should be preserved on any exposed instance prior to upgrading.

## Mentioned in this report

- Vulnerabilities: CVE-2026-76504 (KEV)

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-cisco-catalyst-sd-wan-manager-could-allow-for-authentication-bypass_2026-105

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c086c6e7-dd42-5afe-a590-09e2f3e9822b/cisco-sd-wan-manager-auth-bypass-exploited-in-wild.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
