Threat Landscape

Cisco SD-WAN Manager CVE-2026-76504: CISA KEV. FCEB patch by Oct 3.

Cisco PSIRT published advisory cisco-sa-sdwan-webauth-xr8beuuU on September 30, 2026 (13:00 GMT) for CVE-2026-76504 — a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager (formerly vManage) API session handling. Unauthenticated remote attackers can reach the API as the admin user by crafting a URI-encoded HTTP request. Cisco says PSIRT became aware of active exploitation in September 2026. No workarounds. Victim census / actor: Undisclosed. NEW afternoon: CISA KEV catalogVersion 2026.09.30 (dateReleased 2026-09-30T16:59:23Z / ~9:59 AM PT) adds the CVE — FCEB BOD due 2026-10-03; forensic triage Yes; ransomware Unknown.

Sep 30, 2026 · 3 min read

SD-WAN Manager is the control plane for the fabric. Admin on that plane is not a help-desk ticket — it is config push across the estate.

Primary: Cisco Security Advisory cisco-sa-sdwan-webauth-xr8beuuU, first published 2026-09-30 13:00 GMT. Summary: improper handling of URI encoding in an HTTP request lets an attacker bypass an authentication rule meant to restrict a specific API endpoint. Crafted request → authentication bypass → API access as the admin user. The product is affected regardless of system configuration. CVSS 3.1 base 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). CWE framing in secondary write-ups points at URL-encoding mishandling; Cisco is the primary source for the mechanism.

Exploitation — what Cisco will say, and what it will not. Exploitation and Public Announcements section: “In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.” Strong upgrade recommendation. Source of discovery: found during resolution of a Cisco TAC support case. The advisory does not disclose victim count, when attacks began, who the actors were, or what they did with access; all of that is Undisclosed. CISA KEV — added today. Catalog version 2026.09.30, dateReleased 2026-09-30T16:59:23.0688Z (~9:59 AM PT), added CVE-2026-76504 as “Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability.” FCEB BOD due 2026-10-03. Forensic triage required: Yes. Known ransomware campaign use: Unknown. Same URI-encoding → unauth admin story Cisco shipped this morning — now on the federal clock. Primary: the live KEV JSON feed; the CISA news-events alert page for 2026-09-30 returned Access denied at midday check.

Fixed software (first fixed release per train, Cisco table): earlier than 20.9 → migrate; 20.9 → 20.9.10.1; 20.12 → 20.12.8.2; 20.15 → 20.15.6.1; 20.18 → 20.18.4.1; 26.1 → 26.1.2.1; 26.2 → 26.2.1. Cisco SD-WAN Cloud (Cisco Managed) already on 20.15.605 — no customer action. Secondary (The Hacker News / BleepingComputer): managers last patched only for the May/June 2026 SD-WAN flaws still need this train; that comparison is from those write-ups, not a CyberMerge upgrade matrix.

Hunt before you overwrite forensics. Cisco IoC examples use %6a as URI-encoded j in /%6a_security_check — any one character may be encoded; that hex is an example only. Audit /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for j_security_check activity from unknown/unauthorized IPs, especially users whose names start with viptela-reserved-. False positives possible during normal ops — baseline first. Open a Severity 3 TAC case with CVE-2026-76504 in the title; run request admin-tech before the case so Cisco can review the file. Temporary on-prem mitigation (not a fix): restrict internet exposure; allow only trusted hosts; put control components behind a firewall — Cisco hardening guide already says admin ports (443/22/830) should not face the open internet. Cloud Hosted environments already have that mitigation deployed per Cisco.

POV for the SOC this morning: Fifth actively exploited Catalyst SD-WAN Manager-class zero-day storyline of 2026 per BleepingComputer’s count — treat that as secondary framing, not a Cisco tally. Priority: internet-reachable Managers first; collect admin-tech; patch to the fixed train; do not assume an upgrade alone cleans a confirmed compromise (prior Cisco SD-WAN advisories warned the same). Victim numbers remain Undisclosed. Primary: Cisco PSIRT; BleepingComputer / The Hacker News provided same-day amplification.

Underwrite sheet — sourced only: Cisco advisory cisco-sa-sdwan-webauth-xr8beuuU Sep 30, 2026 13:00 GMT — CVE-2026-76504; CVSS 9.8; unauth remote admin API via URI encoding bypass; affects Catalyst SD-WAN Manager any config; no workarounds; active exploitation Sep 2026 (PSIRT); found via TAC case; fixed trains 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1; Cloud Managed 20.15.605 no action; IoC %6a / j_security_check / viptela-reserved-; admin-tech + Sev3 TAC. BleepingComputer Sep 30 ~10:46 AM ET; The Hacker News Sep 30. Victim count / actor / attack start: Undisclosed. CISA KEV catalog 2026.09.30 dateReleased 2026-09-30T16:59:23Z — CVE-2026-76504 dateAdded 2026-09-30; due 2026-10-03; forensic Yes; ransomware Unknown.

Sources