Cisco Confirms Active Exploitation of a 9.8-Severity SD-WAN Manager Auth Bypass

Cisco's September 30, 2026 advisory and a same-day CISA order describe how encoded characters in an HTTP request let attackers skip login and reach SD-WAN Manager as admin.

EduFabTech · 3 October 2026 · 4 min read · 44 views
An HTTP request with the character "j" hex-encoded as %6a flows past a broken auth filter straight into admin API access, alongside the CVSS 9.8 score and the October 3 federal patch deadline.
EduFabTech · Own work

Cisco published a security advisory on September 30, 2026, disclosing a critical authentication bypass in Catalyst SD-WAN Manager, the controller software that network administrators use to configure and monitor wide-area networks across distributed sites. The flaw, tracked as CVE-2026-76504, carries a CVSS score of 9.8 out of 10, and Cisco's own advisory states that its Product Security Incident Response Team (PSIRT) "became aware of active exploitation of this vulnerability" in September 2026. The same day, the US Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until October 3, 2026 to patch.

How the bypass works

According to Cisco's advisory, the vulnerability sits in how SD-WAN Manager's API handles session-based authentication. The root cause is "improper handling of URI encoding in an HTTP request" — a defect Cisco classifies under CWE-177, the standard weakness category for software that mishandles encoded input. An attacker with no valid credentials can send a specially crafted request to an API endpoint that is supposed to require a login, and the authentication filter fails to recognize the request as one it should block.

Cisco's advisory gives a concrete example: encoding a single character in the request path, such as writing the letter "j" as the hexadecimal sequence %6a, is enough to slip past the check guarding the j_security_check login-handling endpoint. Cisco notes that this is only one example — any single character encoded in the right place in the request can trigger the same bypass. The advisory states the flaw affects the product "regardless of system configuration," meaning there is no optional feature or setting that avoids exposure. A successful exploit gives the attacker API access with the privileges of the admin user, without supplying a password or any user interaction.

A CVSS severity scale with the Critical band lit up and a marker at 9.8, next to panels on active exploitation, the CISA KEV listing, and the federal patch deadline.
A CVSS severity scale with the Critical band lit up and a marker at 9.8, next to panels on active exploitation, the CISA KEV listing, and the federal patch deadline.EduFabTech · Own work

Which versions are exposed

Cisco's advisory lists the affected release trains and their fixes: versions earlier than 20.9 must migrate to a supported fixed release; 20.9 is fixed in 20.9.10.1; 20.12 in 20.12.8.2; 20.15 in 20.15.6.1; 20.18 in 20.18.4.1; 26.1 in 26.1.2.1; and 26.2 in 26.2.1. Cisco states there is no workaround for the underlying flaw — the only mitigation it offers for organizations that cannot patch immediately is restricting network access to the SD-WAN Manager interface from untrusted networks, which reduces exposure but does not close the hole.

Why CISA moved immediately

CISA's September 30, 2026 alert added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog the same day Cisco's advisory went live, describing it as "a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user." Under Binding Operational Directive 26-04, which directs federal civilian agencies to prioritize remediation of cataloged vulnerabilities by risk, the entry carries a due date of October 3, 2026 — a window of roughly three days from the catalog addition. CISA describes the catalog itself as "the authoritative source of vulnerabilities that have been exploited in the wild," which is why confirmed activity, not severity score alone, is what triggers a listing and the deadline that follows. Security researchers at Rapid7 published a corroborating technical note the same day, confirming the CWE-177 classification and the admin-level impact Cisco described — though, like CISA's alert, Rapid7's account draws on Cisco's advisory rather than separate exploitation telemetry.

What it means beyond federal networks

The CISA deadline is a US federal compliance mechanism, not a limit on who is affected. SD-WAN Manager is deployed by universities, research consortia and enterprises worldwide to centrally control routing across multiple campuses or sites, which means a compromised controller can expose everything connected behind it — not just one office network but every site the controller manages. Anyone operating a SD-WAN Manager instance that is reachable from an untrusted network, inside or outside the United States, carries the same exposure Cisco describes, independent of any government deadline.

A three-step diagram showing an unauthenticated request, an encoded character fooling the login filter, and the resulting unauthenticated admin API access.
A three-step diagram showing an unauthenticated request, an encoded character fooling the login filter, and the resulting unauthenticated admin API access.EduFabTech · Own work

A recurring class of bug

For students and engineers studying web application security, CVE-2026-76504 is a current, well-documented instance of a long-running bug family: authentication filters that inspect a request path before it is fully decoded, letting an encoded character slip past a string match that would have caught the same character written literally. The j_security_check endpoint named in Cisco's advisory is a standard Java EE login-handling path, and mismatches between how a web server's routing layer and its authentication layer decode URIs have produced bypasses in other products in the past — which is part of why CWE-177 exists as its own weakness category rather than being folded into generic input validation.

Cisco's advisory and CISA's catalog entry together document a specific encoding trick, the affected releases, the fixed versions, and the date Cisco confirmed exploitation — concrete details that give administrators something to check for, rather than a general instruction to upgrade.

A quick question for readers

Source: Cisco PSIRT

Sources (3)
  1. Cisco PSIRT. Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability. Cisco Security Advisory, 2026. sec.cloudapps.cisco.com ↗ · checked 3 Oct 2026
  2. CISA. CISA Adds One Known Exploited Vulnerability to Catalog. Cybersecurity and Infrastructure Security Agency, 2026. cisa.gov ↗ · checked 3 Oct 2026
  3. Rapid7. Critical Cisco Catalyst SD-WAN Manager API Authentication Bypass Exploited in the Wild (CVE-2026-76504). Rapid7, 2026. rapid7.com ↗ · checked 3 Oct 2026