← Back to Feed CACHED · 2026-10-01 08:28:49 · CACHE_KEY CVE-2026-76504
CVE-2026-76504 · CWE-177 · Disclosed 2026-09-30

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could

ASSESSED — NOISGATE
Vendor
—
—
—
Reassessed
—
—
—
Verdict: —
Do you agree?
01 · The Real Story

Someone left the master key under the doormat, except the doormat is a single URL-encoded character and the door opens every SD-WAN tunnel you own

CVE-2026-76504 is an unauthenticated authentication bypass in Cisco Catalyst SD-WAN Manager (formerly vManage) affecting all supported release trains from 20.9.x through 26.2.x. The flaw lives in the API session management layer: the j_security_check authentication endpoint is protected by a request-routing rule that matches the literal path, but the router also accepts hex-encoded variants like /%6a_security_check (%6a = j). Because the URI is not normalized before the auth decision, the encoded request skips the authentication check entirely and the server issues a valid admin-level JSESSIONID — no credentials required. The admin user holds the netadmin role, which permits all operations including configuration push, credential extraction, and user management across the entire SD-WAN fabric.

Cisco rates this CRITICAL / 9.8 and that score is honest. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) accurately reflects the attack surface: remote, trivial, unauthenticated, no interaction, full CIA impact. Cisco PSIRT confirmed this was exploited in the wild before the patch shipped — a genuine zero-day. CISA added it to the KEV catalog on the same day (September 30, 2026) with a federal remediation deadline of October 3, 2026. There is no workaround. A public weaponized PoC (ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept) was published almost immediately, lowering the exploitation bar to a single Python command. This is the fifth exploited SD-WAN zero-day and the third critical auth bypass in Cisco's SD-WAN control plane in 2026 alone.

"Actively exploited zero-day auth bypass hands unauthenticated attackers full admin over your SD-WAN fabric."
02 · The Attack Path

5 steps from start to impact.

STEP 01

Target Discovery

Attacker identifies a Cisco SD-WAN Manager instance via Shodan (http.title:"Cisco vManage"), Censys, FOFA, or internal network scanning on ports 443/8443. The management interface is typically on the management VLAN reachable from corporate segments. Internet-facing instances number ~450–550 on Shodan/Censys and ~1,000+ on FOFA.
Conditions required:
  • Network path to SD-WAN Manager HTTPS port (443 or 8443)
Where this breaks in practice:
  • Mature orgs restrict management plane to jump hosts or dedicated admin VLANs
  • Internet-facing exposure is limited (~450–1,000 instances globally)
  • Internal-only instances still reachable from any compromised host on the management VLAN
Detection/coverage: Shodan/Censys alerts on org IP space; internal asset inventory should track all SD-WAN Manager instances.
STEP 02

Authentication Bypass via URL Encoding

Attacker sends a POST request to /%6a_security_check with j_username=admin&j_password= (empty password). The request router accepts the hex-encoded path, but the authentication rule matching j_security_check does not fire because the string was never normalized. The auth check is skipped entirely. Any single hex-encoded character in the path works — %6a for j, %5f for _, double-encoding, etc. The public PoC from ShadowForge-Cyber automates this with python3 exploit.py --target <url> --check.
Conditions required:
  • HTTPS reachability to the manager (step 1)
  • No credentials required
Where this breaks in practice:
  • None. Single curl command or one-click PoC. The encoding trick is trivially reproducible.
Detection/coverage: Review /var/log/nms/containers/service-proxy/serviceproxy-access.log for any request containing %6a_security_check or other hex-encoded variants of the j_security_check path.
STEP 03

Admin Session Acquisition

The server returns a valid JSESSIONID cookie bound to the built-in admin account with netadmin role privileges. This session token grants unrestricted access to all /dataservice/ API endpoints. No MFA challenge is issued because the bypass occurs below the authentication layer entirely. The attacker now holds the same API authority as a legitimate administrator.
Conditions required:
  • Successful bypass from step 2
Where this breaks in practice:
  • None — the session is issued automatically.
Detection/coverage: Monitor /var/log/nms/vmanage-server.log for authentication events involving usernames prefixed with viptela-reserved-. Alert on JSESSIONID creation from unexpected source IPs.
STEP 04

Configuration Exfiltration and Fabric Takeover

With admin API access, the attacker queries /dataservice/system/device/controllers and /dataservice/template/device/config/ to exfiltrate running configurations of all managed WAN edges, including pre-shared keys, SNMP communities, IPsec certificates, and routing tables. They can push malicious traffic policies, modify VPN routing to redirect or intercept traffic, create backdoor admin accounts, or disable WAN tunnels — disrupting connectivity across the entire overlay network.
Conditions required:
  • Valid admin session from step 3
  • SD-WAN Manager has connectivity to managed edges (true by design)
Where this breaks in practice:
  • Attacker needs basic SD-WAN operational knowledge to weaponize fabric access beyond config theft, but bulk config export requires only REST API calls.
Detection/coverage: Audit trail in SD-WAN Manager for configuration changes, new user creation, bulk template pushes, and API calls to /dataservice/template/ or /dataservice/system/device/ from non-standard source IPs. SIEM correlation on admin activity spikes.
STEP 05

Persistence and Lateral Movement to Edge Devices

Attacker creates additional admin accounts via the API to maintain access even if the original bypass is patched. Extracted credentials and certificates from device templates enable direct SSH/NETCONF access to individual WAN edge routers, bypassing the manager entirely. Pre-shared keys and SNMP communities harvested from configs can unlock other network infrastructure. The attacker has effectively pivoted from one management plane compromise to persistent control of every managed network device.
Conditions required:
  • Admin API access from step 3
  • Extracted credentials from step 4
  • Network path from manager to edge devices (exists by design)
Where this breaks in practice:
  • Network segmentation between management plane and edge devices may limit direct SSH — but the manager itself has this connectivity by architectural requirement.
Detection/coverage: New user creation alerts in SD-WAN Manager; unexpected SSH sessions to WAN edge routers; certificate usage anomalies; SNMP polling from unauthorized sources.
03 · Compensating Control

1
CRITICAL 9.8→MEDIUM 5.5
SEVERITY REDUCED
Restrict HTTPS access to SD-WAN Manager to authorized management IPs only via firewall ACL — Apply firewall rules or security group policies to limit inbound HTTPS (443/8443) to the SD-WAN Manager to only known jump hosts and admin workstations. This eliminates the attack surface from both internet-facing and untrusted internal segments. Since this CVE is KEV-listed with confirmed active exploitation, the noisgate mitigation SLA is overridden: deploy within hours, not the standard 3-day CRITICAL window. Verify no broad management VLAN routing permits access from general-purpose user segments. This single control breaks the attack path at step 1 for all unauthorized sources.
2
CRITICAL 9.8→CRITICAL 9.8
Deploy SIEM detection rules for bypass IOCs in SD-WAN Manager logs — Forward /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log to your SIEM. Alert on: (1) any POST request containing %6a_security_check or other hex-encoded variants of the j_security_check path, (2) any authentication event for usernames prefixed viptela-reserved-, (3) JSESSIONID creation from unexpected source IPs. This is a detection-only control — it does not prevent exploitation. Deploy immediately alongside the ACL.
3
CRITICAL 9.8→IGNORE 0.0
SEVERITY REDUCED
Upgrade SD-WAN Manager to the fixed release for your branch — Apply the vendor patch: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or 26.2.1. Cloud-managed deployments on 20.15 receive 20.15.605 automatically. Given active exploitation and KEV listing, the noisgate remediation SLA is overridden: patch immediately — within hours for internet-facing instances, within 72 hours maximum for internal-only. Contact Cisco TAC if your branch is below 20.9 to plan migration. After patching, rotate all credentials stored in SD-WAN Manager templates (pre-shared keys, SNMP communities, certificates) as a precaution against prior compromise.
4
CRITICAL 9.8→CRITICAL 9.8
Conduct forensic review of SD-WAN Manager logs for prior compromise — Given zero-day exploitation was confirmed before the patch shipped, assume your instance may already be compromised. Review serviceproxy-access.log for encoded j_security_check requests from any IP, vmanage-server.log for viptela-reserved- sessions, and admin audit logs for unauthorized user creation, template changes, or config exports. Check for unknown admin accounts. Deploy within hours alongside patching.
What doesn't work
  • WAF URL normalization — While a WAF can normalize URL-encoded characters, most SD-WAN Manager deployments do not sit behind a WAF, and Cisco does not support or document this configuration. Even if deployed, attackers can use double-encoding or alternate character positions that may evade normalization rules.
  • MFA on the vManage web portal — The authentication bypass occurs at the API session layer (j_security_check), below the web UI MFA challenge. MFA protects interactive logins through the browser; it does not protect the API endpoint exploited by this CVE.
  • IPS/IDS signature-only detection — A signature for %6a_security_check is trivially evaded by encoding any other character in the path (j%5fsecurity_check, j_security_%63heck, double-encoding). Pattern matching alone is unreliable; network access restriction is the only dependable compensating control.
  • Disabling the REST API — The /dataservice/ API is required for SD-WAN Manager to function. Disabling it breaks controller-to-edge communication, policy push, and monitoring. This is not a viable mitigation.
04 · Intelligence Metadata

The supporting signals.

In-the-Wild ExploitationConfirmed. Cisco PSIRT became aware of active exploitation in September 2026 via a support case investigation. Exploited before the patch was available — a true zero-day. No specific threat actor attributed publicly. This is the fifth exploited SD-WAN zero-day in 2026 (BleepingComputer).
CISA KEV StatusAdded 2026-09-30 (CISA alert). BOD 26-04 federal remediation deadline: October 3, 2026 (3 calendar days). *Note:* User-supplied intel indicated "KEV: No" — this is outdated; CISA added it on disclosure day.
Proof of ConceptPublic weaponized PoC on GitHub: ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept by ShadowForge Cyber. Python exploit with --check (detection) and --cmd (RCE) flags. Trivially reproducible with a single curl --path-as-is command. Horizon3.ai published a Rapid Response technical analysis on disclosure day.
EPSS ScoreNot yet scored (disclosed <24 hours ago; EPSS data lags 24–72 hours). Given active exploitation and public PoC, expect rapid escalation to top-1% percentile once scored.
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — 9.8 CRITICAL. Perfect attack-surface metrics: network-reachable, low complexity, no privileges, no interaction. All three CIA pillars at High. Only misses 10.0 because Scope is Unchanged.
Affected VersionsAll supported Catalyst SD-WAN Manager release trains: 20.9.x, 20.12.x, 20.15.x, 20.18.x, 26.1.x, 26.2.x. Releases prior to 20.9 are end-of-support and must migrate to a supported branch.
Fixed Versions20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1. Cloud-managed: 20.15.605 (auto-applied, no customer action). Third critical auth bypass fix in the SD-WAN control plane in 2026 (after CVE-2026-20127, CVE-2026-20182).
Internet ExposureShodan/Censys: ~450–550 internet-facing instances (http.title:"Cisco vManage"). FOFA: ~1,000+. ZoomEye: ~275. Even internally-only instances are reachable from the management VLAN by design (Rapid7).
Disclosure Date2026-09-30 — zero-day disclosure. Cisco advisory, CISA KEV addition, Horizon3 analysis, and public PoC all published on the same day.
Discovery / CreditNot publicly attributed. Cisco PSIRT discovered via internal support case investigation in September 2026. No external researcher credited in the advisory.

Sources.

  1. Rapid7 Emergent Threat Response
  2. Horizon3.ai Attack Research
  3. CISA KEV Alert (2026-09-30)
  4. BleepingComputer — Cisco SD-WAN Zero-Day
  5. The Hacker News — Cisco Auth Bypass
  6. Field Effect — Active Exploitation Analysis
  7. ShadowForge-Cyber PoC (GitHub)
  8. CyberSecurityNews — SD-WAN 0-Day
05 · The Call

Final Verdict
= UNCHANGED to CRITICAL (9.8/10)

Why this verdict

  • No friction on the attack path: The exploit requires only HTTPS access to the SD-WAN Manager and a single URL-encoded POST request. No credentials, no user interaction, no complex prerequisites, no race conditions. The public PoC reduces the attack to one Python command. Zero downward adjustment.
  • Active zero-day exploitation with KEV listing: Cisco PSIRT confirmed pre-patch exploitation. CISA added to KEV on disclosure day with a 3-day federal deadline. This eliminates any theoretical-only discount and triggers the immediate-action override. Zero downward adjustment.
  • No workaround available: Cisco explicitly states no workaround exists. The only path to risk reduction is patching or network access restriction. This prevents any interim-control discount.
  • Public weaponized PoC available day-zero: ShadowForge-Cyber published a turnkey Python exploit with --check and --cmd modes. The underlying technique is a single hex-encoded character — reproducible in curl. Exploitation barrier is effectively zero. Zero downward adjustment.
  • Role multiplier: SD-WAN Manager IS the network management plane. 100% of installs occupy the high-value network orchestration role by definition — it is the central control plane for the entire SD-WAN fabric. Admin access grants: (1) full configuration read/write across all managed WAN edges, (2) credential and certificate extraction for lateral movement, (3) traffic policy manipulation enabling interception or disruption, (4) new admin account creation for persistence. Blast radius: fleet-scale (every managed network device). Verdict floor: CRITICAL per the canonical high-value-role rule — the bug IS in the orchestration platform, and ≥10% of installs (effectively 100%) occupy that role.
  • Internet exposure is limited but does not reduce the floor: Only ~450–1,000 instances are internet-facing globally. However, every SD-WAN Manager is reachable from the internal management network by architectural requirement. A post-initial-access attacker on any corporate segment with management VLAN routing reaches the target. The limited internet exposure prevents the score from being *raised* but does not justify a downgrade — the floor holds.

Why not higher?

The CVSS 3.1 score of 9.8 is already near the ceiling. The only path to 10.0 would require Scope change (S:C), which does not apply here — the vulnerability's direct impact is contained to the SD-WAN Manager's own authorization context, even though the downstream blast radius to managed devices is enormous. A 10.0 would also require that the attack works without *any* network path, which is not the case.

Why not lower?

Active zero-day exploitation confirmed by Cisco PSIRT before the patch existed. CISA KEV listed same-day. Public weaponized PoC available within hours. No workaround. The component IS the network management plane — there is no deployment scenario where unauthenticated admin access to SD-WAN Manager is low-impact. Every install is a high-value target by definition. Downgrading from CRITICAL would require evidence that the exploit does not work as described, which directly contradicts Cisco's own confirmation and Horizon3's independent validation.

06 · Verification

Crowdsourced verification payload.

Run from any Linux/macOS workstation (or jump host) with curl installed and network access to the SD-WAN Manager HTTPS interface. No authentication or special privileges required. Example: bash cve-2026-76504-check.sh https://10.0.1.50. The script performs a non-destructive probe — it does NOT execute commands or modify state on the target.

noisgate-verify.sh
BASHREAD-ONLYSAFE
#!/usr/bin/env bash
# CVE-2026-76504 — Cisco Catalyst SD-WAN Manager Auth Bypass Check
# Non-destructive probe: tests whether the URL-encoding bypass yields a session.
# Does NOT execute commands or modify any state on the target.
#
# Usage:  bash cve-2026-76504-check.sh <https://sdwan-manager-url>
# Example: bash cve-2026-76504-check.sh https://10.0.1.50
#
# Exit codes:  0 = VULNERABLE  |  1 = PATCHED  |  2 = UNKNOWN
set -euo pipefail

TARGET="${1:-}"
if [[ -z "$TARGET" ]]; then
  echo "Usage: $0 <https://sdwan-manager-url>"
  echo "Example: $0 https://10.0.1.50"
  exit 2
fi
TARGET="${TARGET%/}"

echo "[*] CVE-2026-76504 check against: ${TARGET}"
echo "[*] This is a non-destructive read-only probe."

# Step 1: Confirm target is reachable
HTTP=$(curl -sk -o /dev/null -w '%{http_code}' --connect-timeout 10 "${TARGET}/" 2>/dev/null || echo "000")
if [[ "$HTTP" == "000" ]]; then
  echo "[!] Target unreachable at ${TARGET}"
  echo "UNKNOWN"
  exit 2
fi
echo "[*] Target responded with HTTP ${HTTP}"

# Step 2: Send bypass request — POST to /%6a_security_check with empty password
# --path-as-is prevents curl from normalizing the percent-encoded path
RESP=$(curl -sk -D - -o /dev/null --connect-timeout 10 --path-as-is \
  -X POST "${TARGET}/%6a_security_check" \
  -d "j_username=admin&j_password=" 2>/dev/null)

CODE=$(echo "$RESP" | head -1 | grep -oP '\d{3}' || echo "000")
COOKIE=$(echo "$RESP" | grep -i 'set-cookie.*JSESSIONID' || true)

echo "[*] Bypass endpoint (/%6a_security_check) returned HTTP ${CODE}"

# Step 3: Evaluate result
if [[ -n "$COOKIE" ]]; then
  echo "[!] *** VULNERABLE ***"
  echo "[!] JSESSIONID cookie issued without valid credentials."
  echo "[!] Immediate patching required. See Cisco advisory for fixed releases."
  echo "VULNERABLE"
  exit 0
elif [[ "$CODE" == "401" || "$CODE" == "403" || "$CODE" == "400" ]]; then
  echo "[+] PATCHED — Encoded path correctly rejected (HTTP ${CODE})."
  echo "PATCHED"
  exit 1
elif [[ "$CODE" == "404" ]]; then
  echo "[?] Endpoint not found (HTTP 404). Target may not be a Cisco SD-WAN Manager."
  echo "UNKNOWN"
  exit 2
else
  echo "[?] Inconclusive (HTTP ${CODE}, no session cookie). Manual review recommended."
  echo "UNKNOWN"
  exit 2
fi
Peer Review

What defenders are saying.

Submit a review attribution: handle + country only
0 flags selected · stored anonymously