Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with
Analysis Summary
# Vulnerability: Cisco Catalyst SD-WAN Manager Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-76504
- **CVSS Score:** 9.8 (Critical)
- **CWE:** Improper handling of URI encoding (Hex encoding vulnerability)
## Affected Systems
- **Products:** Cisco Catalyst SD-WAN Manager (formerly vManage)
- **Versions:** Not explicitly listed in the text, but impacts all versions prior to the "fixed release."
- **Configurations:** Systems running the Catalyst SD-WAN Manager API services.
## Vulnerability Description
The flaw exists due to improper handling of URI encoding in HTTP requests sent to the SD-WAN Manager. Specifically, the system fails to correctly process hex-encoded variants of URIs. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP request to the API, allowing them to bypass authentication mechanisms and gain full access to the system with administrative privileges.
## Exploitation
- **Status:** Exploited in the wild (Added to CISA KEV on September 30, 2026).
- **Complexity:** Low (Attacker needs to send a crafted HTTP request).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Full administrative access to the management platform).
- **Integrity:** High (Ability to modify network configurations and monitoring).
- **Availability:** High (Potential to disrupt SD-WAN operations).
## Remediation
### Patches
- Cisco has released fixed software versions for Catalyst SD-WAN Manager. Organizations are advised to upgrade to a **fixed release** immediately. (Consult the official Cisco advisory for specific version mapping).
### Workarounds
- No specific workarounds were provided in the article; immediate patching is the primary recommendation.
- Federal agencies (FCEB) are mandated to apply fixes by **October 3, 2026**.
## Detection
**Indicators of Compromise (IoCs):**
- **Log Review:** Audit `/var/log/nms/containers/service-proxy/serviceproxy-access.log` for entries related to `j_security_check` originating from unknown or unauthorized IP addresses.
- **Log Review:** Audit `/var/log/nms/vmanage-server.log` for `j_security_check` calls for users with names starting with `viptela-reserved-`.
- **API Monitoring:** Hunt for POST requests containing URL-encoded variants of `/j_security_check`.
## References
- CISA Known Exploited Vulnerabilities Catalog: [hXXps://www.cisa.gov/known-exploited-vulnerabilities-catalog]
- Cisco Security Advisory: [hXXps://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html] (Article reference)
- The Hacker News Article: [hXXps://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html]