VORANT. Threat Intelligence Research Sign in Create a free account

Cisco SD-WAN Manager auth bypass flaw patched

elevated vulnerability technologytelecommunications

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

An unauthenticated URL-encoding flaw in Cisco Catalyst SD-WAN Manager lets attackers bypass authentication and gain full admin control; NCSC urges IOC checks before patching.

NCSC-NL published an advisory for a critical vulnerability in Cisco Catalyst SD-WAN Manager caused by improper handling of URL/hex encoding in an API. The flaw allows unauthenticated attackers to bypass authentication mechanisms, gain administrative access, and take full control of affected systems. Cisco has released updates to remediate the issue and has shared indicators of compromise (IOCs) associated with exploitation.

NCSC-NL strongly advises organizations running SD-WAN Manager to check their systems against the published IOCs before applying the security update, implying that exploitation attempts or successful compromises have already been observed in the wild. Given the CVSS v3 score of 9.8, the unauthenticated nature of the attack, and the full administrative takeover impact, this should be treated as an urgent patching priority for any organization operating Cisco Catalyst SD-WAN Manager.

Defenders should prioritize checking for the shared IOCs (see Cisco's advisory referenced by NCSC) prior to patching, then apply the vendor updates as soon as possible. Monitor SD-WAN Manager access logs for anomalous authentication bypass attempts and unexpected administrative account activity.

Mentioned in this report

Vulnerabilities CVE-2026-76504

Detection guidance

Cisco SD-WAN Manager Unauthenticated API Access

ATT&CK T1190

Detects HTTP requests to Cisco SD-WAN Manager API endpoints that succeed without prior authentication, indicated by 200/201 responses to sensitive endpoints without an active session token. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Cisco SD-WAN Manager Unauthenticated API Access
description: Detects successful HTTP requests to Cisco SD-WAN Manager API endpoints
  returning 2xx status codes without a valid authentication token or session cookie,
  indicating potential exploitation of the URL/hex encoding auth bypass vulnerability.
tags:
- attack.t1190
logsource:
  category: proxy
detection:
  selection_api_endpoint:
    cs-uri-stem|contains:
    - /appmgr/
    - /api/v1/
    - /admin/
    cs-method: GET
  selection_success:
    sc-status:
    - 200
    - 201
  filter_authenticated:
    cs-cookie|contains:
    - sessionid
    - auth_token
    - bearer
  condition: selection_api_endpoint and selection_success and not filter_authenticated
falsepositives:
- Legitimate status page health checks from monitoring systems that expect 200 responses
- Pre-authentication API endpoints explicitly designed for unauthenticated access
  (validate against Cisco's documented safe endpoints)
level: high
id: d1e75f17-b0ef-5af7-a71e-8cc56b8d6a5b
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0395.html

Cisco SD-WAN Manager URL Hex Encoding in HTTP Request

ATT&CK T1190

Detects HTTP requests to Cisco SD-WAN Manager containing URL-encoded or hex-encoded segments in the URI path, a signature of the authentication bypass exploitation technique. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Cisco SD-WAN Manager URL Hex Encoding in HTTP Request
description: Detects HTTP requests to Cisco SD-WAN Manager with URL or hex-encoded
  characters embedded in the URI path, indicative of the improper URL/hex encoding
  handling vulnerability being exploited to bypass authentication checks.
tags:
- attack.t1190
logsource:
  category: proxy
detection:
  selection_target:
    cs-host|contains: sd-wan
    cs-uri-stem|contains:
    - /admin
    - /appmgr
    - /api
  selection_encoding:
    cs-uri-stem|contains:
    - '%2e'
    - '%2f'
    - '%5c'
    - '%00'
    - '%252'
    - ..%2f
    - '%x'
  condition: selection_target and selection_encoding
falsepositives:
- Legitimate administrative interfaces using percent-encoding for special characters
  in API parameters
- Proxy or WAF logging that double-encodes legitimate requests
level: medium
id: 3abe5758-ec50-5087-b1a4-40e49d1ac770
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0395.html

Cisco SD-WAN Manager Administrative Account Creation or Privilege Escalation

ATT&CK T1190

Detects HTTP POST/PUT requests to Cisco SD-WAN Manager user management or privilege escalation endpoints following unauthenticated access, indicating post-exploitation account takeover. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Cisco SD-WAN Manager Administrative Account Creation or Privilege Escalation
description: Detects HTTP POST or PUT requests to Cisco SD-WAN Manager account management
  endpoints (user creation, role assignment, admin promotion) without prior authentication,
  suggesting exploitation leading to administrative account compromise.
tags:
- attack.t1190
logsource:
  category: proxy
detection:
  selection_method:
    cs-method:
    - POST
    - PUT
  selection_admin_endpoint:
    cs-uri-stem|contains:
    - /api/v1/users
    - /admin/users
    - /appmgr/users
    - /api/v1/roles
    - /admin/roles
  filter_authenticated:
    cs-cookie|contains:
    - sessionid
    - auth_token
    - bearer
  condition: selection_method and selection_admin_endpoint and not filter_authenticated
falsepositives:
- Documented initial provisioning workflows that require unauthenticated user creation
- API endpoints explicitly designed for first-time admin account bootstrap
level: high
id: 38fc8217-4e38-58e1-8966-da6684b3907a
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0395.html

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0395.html

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,449 reports from 154 sources, 1,924 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs