Cisco has disclosed a critical zero-day vulnerability in Catalyst SD-WAN Manager that attackers are actively exploiting to gain full administrative control of vulnerable systems. The company published an advisory on September 30 confirming exploitation and released fixed software with no available workaround.

The flaw, tracked as CVE-2026-76504, resides in the API’s session-based authentication mechanism. According to Cisco, the vulnerability stems from improper handling of URI encoding in HTTP requests, which lets a crafted request bypass an authentication rule meant to restrict access to a specific API endpoint. A remote attacker with no credentials can exploit this to interact with the API as an admin user. The bug affects all deployments regardless of configuration.

Cisco said its PSIRT became aware of active exploitation in September 2026 but has not disclosed further details about the attacks or the threat actors involved. It did share indicators of compromise, noting that attackers are using the URI-encoded character sequence %6a (representing the letter “j”) in malicious requests.

Detection and Remediation

Security teams investigating potentially compromised systems should check the serviceproxy-access.log file under /var/log/nms/containers/service-proxy and vmanage-server.log under /var/log/nms/ for entries referencing j_security_check originating from unknown or unauthorized IP addresses. Cisco recommends customers collect admin-tech files and open a case with Cisco TAC if compromise is suspected.

Fixed releases are available across supported branches, including 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Cisco strongly urges immediate upgrades, since no mitigation exists for unpatched systems.

Fifth SD-WAN Zero-Day This Year

CVE-2026-76504 marks the fifth SD-WAN Manager or Controller zero-day actively exploited in the wild since the start of 2026, following an information disclosure flaw exploited since 2023, a maximum-severity auth bypass patched in May, and two root-privilege escalation bugs disclosed in June.

CISA has added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to remediate under Binding Operational Directive 26-04. CISA encourages all organizations, not just federal agencies, to prioritize patching this flaw given its potential for granting full administrative control on internet-exposed SD-WAN Manager instances.