Skip to main content
Emerging Threats

CISA Flags Exploited Cisco SD-WAN Flaw

Network equipment room with Cisco router and technicians working in background.

"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request," CISA said.

CISA adds CVE-2026-76504 to the Known Exploited Vulnerabilities list

The U.S. Cybersecurity and Infrastructure Security Agency on Wednesday added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog after reports of active exploitation. The vulnerability carries a CVSS score of 9.8 and, according to CISA, could enable an unauthenticated, remote attacker to gain admin-level access to an affected Cisco Catalyst SD-WAN Manager system by bypassing authentication.

CISA’s placement of the flaw on KEV triggers accelerated mitigation expectations. Federal Civilian Executive Branch agencies have until October 3, 2026, to apply the fixes CISA referenced.

How the vulnerability operates: hex encoding and j_security_check

CISA describes CVE-2026-76504 as a hex encoding flaw tied to improper URI encoding handling in an HTTP request. Successful exploitation, the agency said, can occur when an attacker sends a crafted HTTP request to the product’s API and thereby sidesteps authentication to access the API "as the admin user."

The advisory specifically points defenders to POST requests for URL-encoded variants of "/j_security_check" as the activity pattern to hunt for when looking for evidence of exploit attempts.

Cisco’s published indicators of compromise and guidance

Cisco said it became aware of active exploitation in September 2026 and has published indicators of compromise (IoCs) customers can use to determine whether they have been impacted. Cisco’s recommended log checks include:

  • Audit /var/log/nms/containers/service-proxy/serviceproxy-access.log for entries related to j_security_check from unknown or unauthorized IP addresses.
  • Audit /var/log/nms/vmanage-server.log for entries related to j_security_check from unknown or unauthorized IP addresses, specifically where the user names begin with "viptela-reserved-".

Beyond releasing IoCs and urging upgrades to fixed releases, Cisco did not disclose details about the exploitation activity: the company did not provide information on who is behind the activity, how many organizations have been compromised, or when the first exploitation occurred.

What this means for FCEB agencies, network operators, and security teams

FCEB agencies: The KEV listing creates a formal deadline — agencies have until October 3, 2026 to apply vendor fixes. That timeline converts advisory language into a compliance requirement for affected federal systems.

Network operators and affected enterprises running Catalyst SD-WAN Manager: Cisco’s guidance is clear — upgrade to a fixed release as soon as possible and hunt for POST requests to any URL-encoded variants of "/j_security_check". Operators should review the two log locations Cisco specified for suspicious calls from unknown or unauthorized IP addresses.

Security teams: Use the IoCs Cisco published to triage possible compromise; specifically search serviceproxy-access.log and vmanage-server.log entries for j_security_check activity and user names beginning with "viptela-reserved-". The presence of such entries from unexpected sources should be treated as a high-priority incident candidate.

Threat signals and platform targeting — watchTowr’s assessment

Jake Knott, head of threat intelligence at watchTowr, framed the KEV addition as part of a broader pattern: "Cisco SD-WAN feels like an ever-present staple of the CISA Known Exploited vulnerabilities list, with eight 2026 CVEs landing on KEV this year alone -- this should be an extremely clear signal that attackers have recognized the value of the platform, and this pattern is unlikely to slow down," he said.

Knott went on to note the obvious operational logic: "None of this should surprise anyone. As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it is naturally an attractive target." The combination of an elevated CVSS score, public reports of active exploitation, and multiple SD-WAN-related KEV entries in 2026 underscores why defenders should prioritize hunting and patching for this class of flaws.

Conclusion: CVE-2026-76504 is a high-severity authentication-bypass vulnerability against a widely used network management product. With CISA’s KEV designation, a federal compliance deadline, published IoCs from Cisco, and public commentary pointing to repeated targeting of SD-WAN platforms, organizations that operate Catalyst SD‑WAN Manager systems should treat the advisory as operationally urgent — upgrade to a fixed release and search the prescribed logs for j_security_check activity immediately.

Original story