CVE-2026-76504: Cisco Catalyst SD-WAN Manager Critical Auth Bypass in CISA KEV
CVE-2026-76504 (CWE-287 / CWE-173)
Severity: CRITICAL (CVSS 9.8)
Status: Actively Exploited Zero-Day (Added to CISA KEV Sep 30, 2026)
Affected Systems: Cisco Catalyst SD-WAN Manager (formerly vManage) versions prior to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1
Fixed In: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1
On September 30, 2026, CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of October 3, 2026. Affecting Cisco Catalyst SD-WAN Manager (formerly vManage), this critical CVSS 9.8 flaw enables remote, unauthenticated threat actors to bypass API session authentication and gain administrative control over the SD-WAN controller fabric through crafted URI hex-encoding.
Vulnerability Mechanics & Proxy Normalization Mismatch
Catalyst SD-WAN Manager relies on an internal containerized reverse proxy (service-proxy) to terminate incoming HTTPS API connections and enforce authentication filters before forwarding requests to the internal vmanage-server Java backend. The vulnerability stems from an impedance mismatch in URI path decoding between the proxy layer and backend application server:
Client HTTP Request
│
├──► [URI: /dataservice/%2e%2e/j_security_check]
│
├──► [Reverse Proxy Filter]: Interprets "%2e%2e" as literal string;
│ does not match static security filter rules for "/j_security_check".
│ Request is permitted through without session token!
│
▼
[vManage Backend Java Runtime]:
│
├──► Java servlet container performs secondary URI decoding:
│ "%2e%2e" resolves to ".."
│ Normalizes path to privileged administrative action handler
│
▼
Full administrative API execution without credentials!
Because the reverse proxy security filter examines the raw encoded URI while the backend servlet container normalizes hex-encoded characters prior to dispatching controller actions, the authentication barrier is entirely circumvented. Attackers can push malicious configuration templates, manipulate BGP routing policies, or compromise connected edge routers.
Forensic Log Telemetry
Security teams managing self-hosted Cisco SD-WAN Manager clusters should immediately examine proxy and server access logs for encoded URI patterns:
/var/log/nms/containers/service-proxy/serviceproxy-access.log
/var/log/nms/vmanage-server.log
# Search for hex-encoded traversal attempts against dataservice APIs
grep -E "(%2e%2e|%2E%2E|%2f|%2F)" /var/log/nms/containers/service-proxy/serviceproxy-access.log | grep -i "j_security_check"
Remediation Strategy
- Deploy Patched Builds: Upgrade immediately to Cisco SD-WAN Manager 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Cloud-hosted Cisco SD-WAN environments have been automatically updated by Cisco.
- Restrict Network Ingress: Ensure SD-WAN Manager web management consoles are strictly accessible via internal management subnets and not exposed to the public internet.
- Rotate Controller Credentials: If suspicious log entries matching the traversal pattern are identified, open a Severity 3 case with Cisco TAC and regenerate all controller certificates and administrative passwords.