Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild

Cisco Catalyst SD-WAN Manager API authentication bypass (TL-2026-2820), also tracked as cisco-sa-sdwan-webauth-xr8beuuU, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-30. It has no confirmed attribution, affects Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage), references 1 CVE (CVE-2026-76504), maps to 3 MITRE ATT&CK techniques (T1027, T1078, T1190), and is covered by 9 detection rules and 4 indicators of compromise.

Key facts for TL-2026-2820

Threat ID
TL-2026-2820
Also known as
cisco-sa-sdwan-webauth-xr8beuuU, CSCww79570
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
telecoms, government administration, enterprise, finance
Target regions
Global
Detection rules
9
Indicators of compromise
4

Cisco disclosed CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager (formerly vManage) caused by improper handling of URI encoding in HTTP requests, which Cisco PSIRT confirmed is being actively exploited since September 2026. Fixed releases are available; there is no workaround, and no threat actor has been attributed.

How Cisco Catalyst SD-WAN Manager API authentication bypass works

CVE-2026-76504 (Cisco advisory cisco-sa-sdwan-webauth-xr8beuuU, bug ID CSCww79570, CWE-177 Improper Handling of Multiple Encodings) is a flaw in the API session-based authentication management of Cisco Catalyst SD-WAN Manager. Improper handling of URI encoding in an HTTP request lets a crafted request bypass an authentication rule that is meant to restrict access to a specific API endpoint. An unauthenticated remote attacker who sends such a request can obtain administrative access to the Manager. Cisco rates the flaw CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The advisory states all deployments are affected regardless of configuration.

Cisco PSIRT detected exploitation attempts in September 2026, and the advisory was published on 2026-09-30 (Final, version 1.0). Cisco lists no workaround. It recommends restricting internet access to the system, placing it behind a firewall and allowing only trusted hosts. Cisco-hosted cloud instances were patched automatically in release 20.15.605.

Cisco and BleepingComputer describe the exploit traffic as requests carrying a URI-encoded character, %6a (the letter 'j'), which reaches the j_security_check login handler by a path that skips the authentication rule. Defenders should review /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for j_security_check entries from unknown or unauthorized IPs. They should also look for activity from 'viptela-reserved-' service accounts.

BleepingComputer calls this the fifth actively exploited Cisco SD-WAN zero-day of 2026. The earlier four are CVE-2026-20127, CVE-2026-20182, CVE-2026-20245 and CVE-2026-20262. For CVE-2026-20127, Cisco Talos tracked the exploiting actor as UAT-8616; CISA reported NETCONF-based fabric manipulation and a software-downgrade path to root through CVE-2022-20775. None of that attribution is stated for CVE-2026-76504, so this record treats the actor as unknown. The source material gives no network IOCs, hashes or malware families.

MITRE ATT&CK techniques used in TL-2026-2820

Defense Evasion

T1027 Obfuscated Files or Information

Persistence

T1078 Valid Accounts

Initial Access

T1190 Exploit Public-Facing Application

Affected products and versions in Cisco Catalyst SD-WAN Manager API authentication bypass

  • Cisco — Catalyst SD-WAN Manager (formerly SD-WAN vManage)
    Vulnerable versions: earlier than 20.9; 20.9; 20.12; 20.15; 20.18; 26.1; 26.2
    Fixed in: 20.9.10.1; 20.12.8.2; 20.15.6.1; 20.18.4.1; 26.1.2.1; 26.2.1

Remediation for Cisco Catalyst SD-WAN Manager API authentication bypass

Patches

  • 20.9 -> 20.9.10.1
  • 20.12 -> 20.12.8.2
  • 20.15 -> 20.15.6.1
  • 20.18 -> 20.18.4.1
  • 26.1 -> 26.1.2.1
  • 26.2 -> 26.2.1
  • Releases earlier than 20.9: migrate to a fixed release
  • Cisco-hosted cloud instances patched automatically in 20.15.605

Immediate actions

  • Upgrade Catalyst SD-WAN Manager to a fixed release: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1
  • Restrict internet exposure of SD-WAN Manager; place it behind a firewall and allow only trusted hosts
  • Review serviceproxy-access.log and vmanage-server.log for j_security_check requests containing %6a from unknown IPs
  • Review use of viptela-reserved- service accounts

Workarounds

  • None available per Cisco; mitigate by limiting network access to trusted hosts only

Longer-term hardening

  • Keep the SD-WAN management plane off the public internet and reachable only from trusted management networks
  • Forward SD-WAN Manager service-proxy and server logs to a SIEM with alerting on encoded j_security_check requests

CVEs associated with Cisco Catalyst SD-WAN Manager API authentication bypass

CVE-2026-76504

Weaknesses (CWE) in Cisco Catalyst SD-WAN Manager API authentication bypass

CWE-177

Timeline of Cisco Catalyst SD-WAN Manager API authentication bypass

  • Earlier 2026 Cisco SD-WAN zero-day CVE-2026-20127 disclosed; Cisco Talos tracks the exploiting actor as UAT-8616 (first of five exploited SD-WAN zero-days this year)
  • CISA flagged another Catalyst SD-WAN Manager bug, CVE-2026-20133, as exploited (Help Net Security), showing sustained targeting of the Manager product before this flaw
  • CVE-2026-20182, an SD-WAN authentication bypass giving admin access, exploited as a zero-day (May 2026 per BleepingComputer; exact day not stated)
  • CVE-2026-20245 and CVE-2026-20262, root privilege escalation flaws in Cisco SD-WAN, exploited as zero-days (June 2026 per BleepingComputer; exact day not stated)
  • Cisco PSIRT detected exploitation attempts against CVE-2026-76504 in September 2026 (exact day not stated)
  • BleepingComputer reported the flaw as the fifth actively exploited Cisco SD-WAN zero-day of 2026, after CVE-2026-20127, CVE-2026-20182, CVE-2026-20245 and CVE-2026-20262
  • Fixed releases available: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1; Cisco-hosted cloud instances auto-patched in 20.15.605
  • Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU (Final v1.0) rating CVE-2026-76504 CVSS 9.8 with confirmed active exploitation and no workaround

Sources cited for Cisco Catalyst SD-WAN Manager API authentication bypass

More in vulnerability

Detection coverage for TL-2026-2820

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2820 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats