Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
Cisco Catalyst SD-WAN Manager API authentication bypass (TL-2026-2820), also tracked as cisco-sa-sdwan-webauth-xr8beuuU, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-30. It has no confirmed attribution, affects Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage), references 1 CVE (CVE-2026-76504), maps to 3 MITRE ATT&CK techniques (T1027, T1078, T1190), and is covered by 9 detection rules and 4 indicators of compromise.
Key facts for TL-2026-2820
- Threat ID
- TL-2026-2820
- Also known as
- cisco-sa-sdwan-webauth-xr8beuuU, CSCww79570
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- telecoms, government administration, enterprise, finance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 4
Cisco disclosed CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager (formerly vManage) caused by improper handling of URI encoding in HTTP requests, which Cisco PSIRT confirmed is being actively exploited since September 2026. Fixed releases are available; there is no workaround, and no threat actor has been attributed.
How Cisco Catalyst SD-WAN Manager API authentication bypass works
CVE-2026-76504 (Cisco advisory cisco-sa-sdwan-webauth-xr8beuuU, bug ID CSCww79570, CWE-177 Improper Handling of Multiple Encodings) is a flaw in the API session-based authentication management of Cisco Catalyst SD-WAN Manager. Improper handling of URI encoding in an HTTP request lets a crafted request bypass an authentication rule that is meant to restrict access to a specific API endpoint. An unauthenticated remote attacker who sends such a request can obtain administrative access to the Manager. Cisco rates the flaw CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The advisory states all deployments are affected regardless of configuration.
Cisco PSIRT detected exploitation attempts in September 2026, and the advisory was published on 2026-09-30 (Final, version 1.0). Cisco lists no workaround. It recommends restricting internet access to the system, placing it behind a firewall and allowing only trusted hosts. Cisco-hosted cloud instances were patched automatically in release 20.15.605.
Cisco and BleepingComputer describe the exploit traffic as requests carrying a URI-encoded character, %6a (the letter 'j'), which reaches the j_security_check login handler by a path that skips the authentication rule. Defenders should review /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for j_security_check entries from unknown or unauthorized IPs. They should also look for activity from 'viptela-reserved-' service accounts.
BleepingComputer calls this the fifth actively exploited Cisco SD-WAN zero-day of 2026. The earlier four are CVE-2026-20127, CVE-2026-20182, CVE-2026-20245 and CVE-2026-20262. For CVE-2026-20127, Cisco Talos tracked the exploiting actor as UAT-8616; CISA reported NETCONF-based fabric manipulation and a software-downgrade path to root through CVE-2022-20775. None of that attribution is stated for CVE-2026-76504, so this record treats the actor as unknown. The source material gives no network IOCs, hashes or malware families.
MITRE ATT&CK techniques used in TL-2026-2820
Defense Evasion
T1027 Obfuscated Files or Information
Persistence
Initial Access
Affected products and versions in Cisco Catalyst SD-WAN Manager API authentication bypass
- Cisco — Catalyst SD-WAN Manager (formerly SD-WAN vManage)
Vulnerable versions: earlier than 20.9; 20.9; 20.12; 20.15; 20.18; 26.1; 26.2
Fixed in: 20.9.10.1; 20.12.8.2; 20.15.6.1; 20.18.4.1; 26.1.2.1; 26.2.1
Remediation for Cisco Catalyst SD-WAN Manager API authentication bypass
Patches
- 20.9 -> 20.9.10.1
- 20.12 -> 20.12.8.2
- 20.15 -> 20.15.6.1
- 20.18 -> 20.18.4.1
- 26.1 -> 26.1.2.1
- 26.2 -> 26.2.1
- Releases earlier than 20.9: migrate to a fixed release
- Cisco-hosted cloud instances patched automatically in 20.15.605
Immediate actions
- Upgrade Catalyst SD-WAN Manager to a fixed release: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1
- Restrict internet exposure of SD-WAN Manager; place it behind a firewall and allow only trusted hosts
- Review serviceproxy-access.log and vmanage-server.log for j_security_check requests containing %6a from unknown IPs
- Review use of viptela-reserved- service accounts
Workarounds
- None available per Cisco; mitigate by limiting network access to trusted hosts only
Longer-term hardening
- Keep the SD-WAN management plane off the public internet and reachable only from trusted management networks
- Forward SD-WAN Manager service-proxy and server logs to a SIEM with alerting on encoded j_security_check requests
CVEs associated with Cisco Catalyst SD-WAN Manager API authentication bypass
Weaknesses (CWE) in Cisco Catalyst SD-WAN Manager API authentication bypass
CWE-177
Timeline of Cisco Catalyst SD-WAN Manager API authentication bypass
- Earlier 2026 Cisco SD-WAN zero-day CVE-2026-20127 disclosed; Cisco Talos tracks the exploiting actor as UAT-8616 (first of five exploited SD-WAN zero-days this year)
- CISA flagged another Catalyst SD-WAN Manager bug, CVE-2026-20133, as exploited (Help Net Security), showing sustained targeting of the Manager product before this flaw
- CVE-2026-20182, an SD-WAN authentication bypass giving admin access, exploited as a zero-day (May 2026 per BleepingComputer; exact day not stated)
- CVE-2026-20245 and CVE-2026-20262, root privilege escalation flaws in Cisco SD-WAN, exploited as zero-days (June 2026 per BleepingComputer; exact day not stated)
- Cisco PSIRT detected exploitation attempts against CVE-2026-76504 in September 2026 (exact day not stated)
- BleepingComputer reported the flaw as the fifth actively exploited Cisco SD-WAN zero-day of 2026, after CVE-2026-20127, CVE-2026-20182, CVE-2026-20245 and CVE-2026-20262
- Fixed releases available: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1; Cisco-hosted cloud instances auto-patched in 20.15.605
- Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU (Final v1.0) rating CVE-2026-76504 CVSS 9.8 with confirmed active exploitation and no workaround
Sources cited for Cisco Catalyst SD-WAN Manager API authentication bypass
- Cisco Security Advisory cisco-sa-sdwan-webauth-xr8beuuU
- Cisco warns of new SD-WAN authentication bypass zero-day exploited in attacks (BleepingComputer)
- NVD - CVE-2026-76504
- MS-ISAC: Multiple Vulnerabilities in Cisco Catalyst SD-WAN Products Could Allow for Authentication Bypass (context: CVE-2026-20127)
- Help Net Security: Threat actor leveraged Cisco SD-WAN zero-day since 2023 (CVE-2026-20127)
- NVD - CVE-2026-20127 (earlier SD-WAN zero-day)
- NVD - CVE-2026-20182 (earlier SD-WAN zero-day)
More in vulnerability
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution
Detection coverage for TL-2026-2820
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2820 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.