Someone left the master key under the doormat, except the doormat is a single URL-encoded character and the door opens every SD-WAN tunnel you own
CVE-2026-76504 is an unauthenticated authentication bypass in Cisco Catalyst SD-WAN Manager (formerly vManage) affecting all supported release trains from 20.9.x through 26.2.x. The flaw lives in the API session management layer: the j_security_check authentication endpoint is protected by a request-routing rule that matches the literal path, but the router also accepts hex-encoded variants like /%6a_security_check (%6a = j). Because the URI is not normalized before the auth decision, the encoded request skips the authentication check entirely and the server issues a valid admin-level JSESSIONID — no credentials required. The admin user holds the netadmin role, which permits all operations including configuration push, credential extraction, and user management across the entire SD-WAN fabric.
Cisco rates this CRITICAL / 9.8 and that score is honest. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) accurately reflects the attack surface: remote, trivial, unauthenticated, no interaction, full CIA impact. Cisco PSIRT confirmed this was exploited in the wild before the patch shipped — a genuine zero-day. CISA added it to the KEV catalog on the same day (September 30, 2026) with a federal remediation deadline of October 3, 2026. There is no workaround. A public weaponized PoC (ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept) was published almost immediately, lowering the exploitation bar to a single Python command. This is the fifth exploited SD-WAN zero-day and the third critical auth bypass in Cisco's SD-WAN control plane in 2026 alone.
5 steps from start to impact.
Target Discovery
http.title:"Cisco vManage"), Censys, FOFA, or internal network scanning on ports 443/8443. The management interface is typically on the management VLAN reachable from corporate segments. Internet-facing instances number ~450–550 on Shodan/Censys and ~1,000+ on FOFA.- Network path to SD-WAN Manager HTTPS port (443 or 8443)
- Mature orgs restrict management plane to jump hosts or dedicated admin VLANs
- Internet-facing exposure is limited (~450–1,000 instances globally)
- Internal-only instances still reachable from any compromised host on the management VLAN
Authentication Bypass via URL Encoding
/%6a_security_check with j_username=admin&j_password= (empty password). The request router accepts the hex-encoded path, but the authentication rule matching j_security_check does not fire because the string was never normalized. The auth check is skipped entirely. Any single hex-encoded character in the path works — %6a for j, %5f for _, double-encoding, etc. The public PoC from ShadowForge-Cyber automates this with python3 exploit.py --target <url> --check.- HTTPS reachability to the manager (step 1)
- No credentials required
- None. Single curl command or one-click PoC. The encoding trick is trivially reproducible.
/var/log/nms/containers/service-proxy/serviceproxy-access.log for any request containing %6a_security_check or other hex-encoded variants of the j_security_check path.Admin Session Acquisition
JSESSIONID cookie bound to the built-in admin account with netadmin role privileges. This session token grants unrestricted access to all /dataservice/ API endpoints. No MFA challenge is issued because the bypass occurs below the authentication layer entirely. The attacker now holds the same API authority as a legitimate administrator.- Successful bypass from step 2
- None — the session is issued automatically.
/var/log/nms/vmanage-server.log for authentication events involving usernames prefixed with viptela-reserved-. Alert on JSESSIONID creation from unexpected source IPs.Configuration Exfiltration and Fabric Takeover
/dataservice/system/device/controllers and /dataservice/template/device/config/ to exfiltrate running configurations of all managed WAN edges, including pre-shared keys, SNMP communities, IPsec certificates, and routing tables. They can push malicious traffic policies, modify VPN routing to redirect or intercept traffic, create backdoor admin accounts, or disable WAN tunnels — disrupting connectivity across the entire overlay network.- Valid admin session from step 3
- SD-WAN Manager has connectivity to managed edges (true by design)
- Attacker needs basic SD-WAN operational knowledge to weaponize fabric access beyond config theft, but bulk config export requires only REST API calls.
/dataservice/template/ or /dataservice/system/device/ from non-standard source IPs. SIEM correlation on admin activity spikes.Persistence and Lateral Movement to Edge Devices
- Admin API access from step 3
- Extracted credentials from step 4
- Network path from manager to edge devices (exists by design)
- Network segmentation between management plane and edge devices may limit direct SSH — but the manager itself has this connectivity by architectural requirement.
/var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log to your SIEM. Alert on: (1) any POST request containing %6a_security_check or other hex-encoded variants of the j_security_check path, (2) any authentication event for usernames prefixed viptela-reserved-, (3) JSESSIONID creation from unexpected source IPs. This is a detection-only control — it does not prevent exploitation. Deploy immediately alongside the ACL.serviceproxy-access.log for encoded j_security_check requests from any IP, vmanage-server.log for viptela-reserved- sessions, and admin audit logs for unauthorized user creation, template changes, or config exports. Check for unknown admin accounts. Deploy within hours alongside patching.- WAF URL normalization — While a WAF can normalize URL-encoded characters, most SD-WAN Manager deployments do not sit behind a WAF, and Cisco does not support or document this configuration. Even if deployed, attackers can use double-encoding or alternate character positions that may evade normalization rules.
- MFA on the vManage web portal — The authentication bypass occurs at the API session layer (
j_security_check), below the web UI MFA challenge. MFA protects interactive logins through the browser; it does not protect the API endpoint exploited by this CVE. - IPS/IDS signature-only detection — A signature for
%6a_security_checkis trivially evaded by encoding any other character in the path (j%5fsecurity_check,j_security_%63heck, double-encoding). Pattern matching alone is unreliable; network access restriction is the only dependable compensating control. - Disabling the REST API — The
/dataservice/API is required for SD-WAN Manager to function. Disabling it breaks controller-to-edge communication, policy push, and monitoring. This is not a viable mitigation.
The supporting signals.
| In-the-Wild Exploitation | Confirmed. Cisco PSIRT became aware of active exploitation in September 2026 via a support case investigation. Exploited before the patch was available — a true zero-day. No specific threat actor attributed publicly. This is the fifth exploited SD-WAN zero-day in 2026 (BleepingComputer). |
|---|---|
| CISA KEV Status | Added 2026-09-30 (CISA alert). BOD 26-04 federal remediation deadline: October 3, 2026 (3 calendar days). *Note:* User-supplied intel indicated "KEV: No" — this is outdated; CISA added it on disclosure day. |
| Proof of Concept | Public weaponized PoC on GitHub: ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept by ShadowForge Cyber. Python exploit with --check (detection) and --cmd (RCE) flags. Trivially reproducible with a single curl --path-as-is command. Horizon3.ai published a Rapid Response technical analysis on disclosure day. |
| EPSS Score | Not yet scored (disclosed <24 hours ago; EPSS data lags 24–72 hours). Given active exploitation and public PoC, expect rapid escalation to top-1% percentile once scored. |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — 9.8 CRITICAL. Perfect attack-surface metrics: network-reachable, low complexity, no privileges, no interaction. All three CIA pillars at High. Only misses 10.0 because Scope is Unchanged. |
| Affected Versions | All supported Catalyst SD-WAN Manager release trains: 20.9.x, 20.12.x, 20.15.x, 20.18.x, 26.1.x, 26.2.x. Releases prior to 20.9 are end-of-support and must migrate to a supported branch. |
| Fixed Versions | 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1. Cloud-managed: 20.15.605 (auto-applied, no customer action). Third critical auth bypass fix in the SD-WAN control plane in 2026 (after CVE-2026-20127, CVE-2026-20182). |
| Internet Exposure | Shodan/Censys: ~450–550 internet-facing instances (http.title:"Cisco vManage"). FOFA: ~1,000+. ZoomEye: ~275. Even internally-only instances are reachable from the management VLAN by design (Rapid7). |
| Disclosure Date | 2026-09-30 — zero-day disclosure. Cisco advisory, CISA KEV addition, Horizon3 analysis, and public PoC all published on the same day. |
| Discovery / Credit | Not publicly attributed. Cisco PSIRT discovered via internal support case investigation in September 2026. No external researcher credited in the advisory. |
Sources.
Why this verdict
- No friction on the attack path: The exploit requires only HTTPS access to the SD-WAN Manager and a single URL-encoded POST request. No credentials, no user interaction, no complex prerequisites, no race conditions. The public PoC reduces the attack to one Python command. Zero downward adjustment.
- Active zero-day exploitation with KEV listing: Cisco PSIRT confirmed pre-patch exploitation. CISA added to KEV on disclosure day with a 3-day federal deadline. This eliminates any theoretical-only discount and triggers the immediate-action override. Zero downward adjustment.
- No workaround available: Cisco explicitly states no workaround exists. The only path to risk reduction is patching or network access restriction. This prevents any interim-control discount.
- Public weaponized PoC available day-zero: ShadowForge-Cyber published a turnkey Python exploit with
--checkand--cmdmodes. The underlying technique is a single hex-encoded character — reproducible in curl. Exploitation barrier is effectively zero. Zero downward adjustment. - Role multiplier: SD-WAN Manager IS the network management plane. 100% of installs occupy the high-value network orchestration role by definition — it is the central control plane for the entire SD-WAN fabric. Admin access grants: (1) full configuration read/write across all managed WAN edges, (2) credential and certificate extraction for lateral movement, (3) traffic policy manipulation enabling interception or disruption, (4) new admin account creation for persistence. Blast radius: fleet-scale (every managed network device). Verdict floor: CRITICAL per the canonical high-value-role rule — the bug IS in the orchestration platform, and ≥10% of installs (effectively 100%) occupy that role.
- Internet exposure is limited but does not reduce the floor: Only ~450–1,000 instances are internet-facing globally. However, every SD-WAN Manager is reachable from the internal management network by architectural requirement. A post-initial-access attacker on any corporate segment with management VLAN routing reaches the target. The limited internet exposure prevents the score from being *raised* but does not justify a downgrade — the floor holds.
Why not higher?
The CVSS 3.1 score of 9.8 is already near the ceiling. The only path to 10.0 would require Scope change (S:C), which does not apply here — the vulnerability's direct impact is contained to the SD-WAN Manager's own authorization context, even though the downstream blast radius to managed devices is enormous. A 10.0 would also require that the attack works without *any* network path, which is not the case.
Why not lower?
Active zero-day exploitation confirmed by Cisco PSIRT before the patch existed. CISA KEV listed same-day. Public weaponized PoC available within hours. No workaround. The component IS the network management plane — there is no deployment scenario where unauthenticated admin access to SD-WAN Manager is low-impact. Every install is a high-value target by definition. Downgrading from CRITICAL would require evidence that the exploit does not work as described, which directly contradicts Cisco's own confirmation and Horizon3's independent validation.
Crowdsourced verification payload.
Run from any Linux/macOS workstation (or jump host) with curl installed and network access to the SD-WAN Manager HTTPS interface. No authentication or special privileges required. Example: bash cve-2026-76504-check.sh https://10.0.1.50. The script performs a non-destructive probe — it does NOT execute commands or modify state on the target.
#!/usr/bin/env bash
# CVE-2026-76504 — Cisco Catalyst SD-WAN Manager Auth Bypass Check
# Non-destructive probe: tests whether the URL-encoding bypass yields a session.
# Does NOT execute commands or modify any state on the target.
#
# Usage: bash cve-2026-76504-check.sh <https://sdwan-manager-url>
# Example: bash cve-2026-76504-check.sh https://10.0.1.50
#
# Exit codes: 0 = VULNERABLE | 1 = PATCHED | 2 = UNKNOWN
set -euo pipefail
TARGET="${1:-}"
if [[ -z "$TARGET" ]]; then
echo "Usage: $0 <https://sdwan-manager-url>"
echo "Example: $0 https://10.0.1.50"
exit 2
fi
TARGET="${TARGET%/}"
echo "[*] CVE-2026-76504 check against: ${TARGET}"
echo "[*] This is a non-destructive read-only probe."
# Step 1: Confirm target is reachable
HTTP=$(curl -sk -o /dev/null -w '%{http_code}' --connect-timeout 10 "${TARGET}/" 2>/dev/null || echo "000")
if [[ "$HTTP" == "000" ]]; then
echo "[!] Target unreachable at ${TARGET}"
echo "UNKNOWN"
exit 2
fi
echo "[*] Target responded with HTTP ${HTTP}"
# Step 2: Send bypass request — POST to /%6a_security_check with empty password
# --path-as-is prevents curl from normalizing the percent-encoded path
RESP=$(curl -sk -D - -o /dev/null --connect-timeout 10 --path-as-is \
-X POST "${TARGET}/%6a_security_check" \
-d "j_username=admin&j_password=" 2>/dev/null)
CODE=$(echo "$RESP" | head -1 | grep -oP '\d{3}' || echo "000")
COOKIE=$(echo "$RESP" | grep -i 'set-cookie.*JSESSIONID' || true)
echo "[*] Bypass endpoint (/%6a_security_check) returned HTTP ${CODE}"
# Step 3: Evaluate result
if [[ -n "$COOKIE" ]]; then
echo "[!] *** VULNERABLE ***"
echo "[!] JSESSIONID cookie issued without valid credentials."
echo "[!] Immediate patching required. See Cisco advisory for fixed releases."
echo "VULNERABLE"
exit 0
elif [[ "$CODE" == "401" || "$CODE" == "403" || "$CODE" == "400" ]]; then
echo "[+] PATCHED — Encoded path correctly rejected (HTTP ${CODE})."
echo "PATCHED"
exit 1
elif [[ "$CODE" == "404" ]]; then
echo "[?] Endpoint not found (HTTP 404). Target may not be a Cisco SD-WAN Manager."
echo "UNKNOWN"
exit 2
else
echo "[?] Inconclusive (HTTP ${CODE}, no session cookie). Manual review recommended."
echo "UNKNOWN"
exit 2
fi