CVE-2026-76504 is an actively exploited authentication bypass in Cisco Catalyst SD-WAN Manager, the control plane administrators use to run a Cisco SD-WAN fabric. This is not a flaw in an individual branch router: Manager centrally provisions edge devices, pushes network policy, manages certificates and software upgrades, and exposes operational visibility across the WAN. An attacker who reaches a vulnerable Manager API needs no account, no password, and no user interaction to obtain the API privileges of the admin user.
That makes the product’s placement matter. Large enterprises, service providers, and branch-heavy organisations use it to operate connectivity across branches, campuses, data centres, and cloud environments. Healthcare, finance, government, retail, manufacturing, energy, logistics, and managed-service environments are among the kinds of deployments where a central WAN management console carries especially broad operational authority.
URI encoding slips past the authentication check
Cisco describes the bug as improper handling of URI encoding in session-based API authentication. Put simply, the server is meant to recognise a protected API endpoint and demand authentication before serving it. A crafted HTTP request can encode a character in its URI such that the authentication rule no longer recognises the path it should protect. The request then reaches the API as though it were the administrator.
Cisco assigns CWE-177, Improper Handling of URL Encoding, and says the problem affects Manager regardless of system configuration. The exact affected source file, function, vulnerable condition, and patch implementation are not public; this is proprietary software and Cisco has published fixed releases rather than a code diff. Its advisory includes indicators involving encoded-character requests to j_security_check, but stresses that encoding any single character may work. Those examples are useful hunting detail, not a runnable exploit.
Exploitation is confirmed; upgrade is the fix
Cisco says its PSIRT learned of active exploitation during September 2026, after the issue was identified while resolving a TAC support case. The attacker, victims, campaign, start date, and number of affected customers have not been publicly identified. CVE-2026-76504 entered CISA’s Known Exploited Vulnerabilities catalogue on September 30, with an October 3 remediation due date reported in the KEV notice. No standalone public proof of concept, Metasploit module, Nuclei template, Exploit-DB entry, or runnable exploit repository had surfaced as of October 1; that does not rule out privately held exploit code.
A patch exists, and there is no workaround that removes the flaw. Upgrade on-premises Manager installations to the first fixed release in their train: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Releases earlier than 20.9 require migration to a supported fixed release. Cisco Managed SD-WAN Cloud was fixed in 20.15.605 and requires no customer action.
Until the upgrade is complete, restrict Manager access from unsecured networks and allow required internet access only from known trusted hosts. Collect admin-tech bundles from every Manager, including cluster and disaster-recovery nodes, before upgrading, then use Cisco TAC’s IOC scan; Cisco notes that scan is not a full forensic investigation. Review logs for encoded j_security_check requests and viptela-reserved- usernames, but assess them in context because they can occur normally.
For teams that run this platform, the practical priority is exposure reduction and an expedited upgrade, not trying to tune around the bypass. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs, which is useful when a management-plane issue moves from disclosure to active exploitation this quickly.




