"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," Cisco warned — a brief, stark sentence that crystallizes the urgency for organizations running Catalyst SD‑WAN Manager.
Cisco PSIRT alert on CVE-2026-76504
Cisco released security updates to address a critical zero‑day in Catalyst SD‑WAN Manager tracked as CVE-2026-76504 and said attackers are actively exploiting the flaw to escalate to administrative privileges. The company "strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability," Cisco wrote on Wednesday. Catalyst SD‑WAN Manager, formerly known as SD‑WAN vManage, is network management software that permits administrators to monitor and manage up to 6,000 SD‑WAN devices from a single dashboard.
How CVE-2026-76504 bypasses SD‑WAN API authentication
The vulnerability affects all deployments "regardless of system configuration." Cisco identified the weakness in API session‑based authentication management and said it allows unauthenticated attackers to access vulnerable systems remotely with admin privileges. According to Cisco, "this vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint." An attacker can exploit the issue by "sending a crafted HTTP request to the API of the affected system."

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageIndicators, logs, and immediate forensic steps
- Cisco provided specific indicators of compromise (IOCs): threat actors are using %6a as the URI‑encoded character "j" in malicious requests.
- Administrators investigating possible compromise should check the serviceproxy-access.log file at /var/log/nms/containers/service-proxy and the vmanage-server.log file at /var/log/nms/ for entries related to j_security_check originating from unknown or unauthorized IP addresses.
- For help determining whether a Cisco Catalyst SD‑WAN Manager has been compromised, Cisco advised that "customers may open a case with the Cisco TAC" and that admins should first collect admin-tech files to support a review.
Why Catalyst SD‑WAN Manager customers are exposed
Two facts in Cisco's advisory increase the operational risk: the product is designed to centrally control thousands of edge devices, and the vulnerability gives remote, unauthenticated attackers admin privileges on any affected deployment. Cisco also noted it would not limit applicability by environment: the flaw "affects all deployments regardless of system configuration." While Cisco did not disclose further technical details about active attacks, it did publish the encoded‑character IOC and the log locations administrators should inspect.
How technologists, affected enterprises, and adversaries are likely to respond
- Technologists and security teams: will prioritize upgrading to Cisco's fixed software release and searching the specified logs (serviceproxy-access.log and vmanage-server.log) for j_security_check entries and %6a‑encoded requests; they may open a Cisco TAC case and collect admin‑tech files to support incident validation.
- Affected enterprises and procurement leaders: must assess exposure across any Catalyst SD‑WAN Manager instances (each of which may manage up to 6,000 devices) and schedule rapid patching or compensating controls given that the advisory covers "all deployments regardless of system configuration."
- Adversaries and threat actors: now have a published tactic and an IOC (%6a as "j") to reuse; Cisco's confirmation that exploitation is active increases the incentive for operators to probe SD‑WAN management interfaces for the same URI‑encoding bypass.
This advisory is the fifth SD‑WAN zero‑day actively exploited in the wild since the start of 2026. Cisco also warned in early June of two other exploited SD‑WAN zero‑days — CVE‑2026‑20245 and CVE‑2026‑20262 — that were abused to gain root privileges. Separate tracking by the Cybersecurity and Infrastructure Security Agency notes that since November 2021 it has tagged 90 Cisco vulnerabilities as exploited in the wild, including four in Cisco Catalyst SD‑WAN Manager and seven abused by ransomware operations.
The concrete next steps are narrow and immediate: upgrade to the fixed release Cisco has issued, scan the named logs for j_security_check and %6a indicators, collect admin‑tech files if compromise is suspected, and open a case with Cisco TAC. Cisco shared limited operational details about the ongoing attacks, but the combination of a universal‑impact authentication bypass and published IOCs means defenders have both a clear priority and measurable signals to hunt.




