CVE-2026-76504

catalyst_sd-wan_manager: Improper Handling of URL Encoding (Hex Encoding) (CVE-2026-76504)

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2026-76504 scores CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning it is network-exploitable with no credentials, no user interaction, and low attack complexity — placing it in the highest urgency tier for any organisation running Cisco Catalyst SD-WAN Manager. The SD-WAN Manager is the centralised control plane for WAN fabric; admin-level API access allows an attacker to rewrite routing policies, manipulate VPN tunnels, and export device certificates, effectively owning the entire SD-WAN overlay. NIS2-scoped organisations with SD-WAN connecting critical sites or OT-adjacent networks should treat this as P1 regardless of whether the manager is directly internet-facing — reachability from a DMZ or a compromised internal host is sufficient for exploitation. Although CISA has not flagged known ransomware campaign use at the time of KEV listing, the authentication-bypass primitive is highly attractive for initial access brokers and supply-chain-style attacks against managed WAN infrastructure.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply the vendor patch: Cisco has released a fix for CVE-2026-76504 — upgrade all affected Cisco Catalyst SD-WAN Manager instances to the patched version immediately (consult the Cisco Security Advisory for the exact build number, as no specific version string is available in the current context).
  • Restrict API exposure: Ensure the SD-WAN Manager API (TCP 443, TCP 8443) is not reachable from the internet or untrusted network segments — enforce firewall rules to limit access to a dedicated out-of-band management network or VPN-only access.
  • Invalidate all active API sessions and rotate credentials: Terminate all current API sessions on the SD-WAN Manager and rotate admin credentials (local accounts and any TACACS+/RADIUS shared secrets), as an attacker with admin-level access may have created persistent backdoor accounts.
  • Enforce IP allowlisting: Restrict SD-WAN Manager API access to a defined set of authorised management hosts via ACLs on upstream firewalls or the SD-WAN Manager's built-in access control filter.
  • Preserve and forward logs: Confirm that HTTP access logs and API audit logs are being forwarded to your SIEM before any forensic evidence is overwritten by log rotation.

Runbook · Step 2

Mitigation layers

  • Network segmentation: Place the SD-WAN Manager management interface (TCP 443/8443) exclusively on a dedicated management VLAN with no direct internet or production-VLAN reachability.
  • WAF/IPS rule: Block or alert on HTTP requests containing hex-encoded URI sequences (e.g. %2F, %2E, double-encoded %25xx patterns) targeting the SD-WAN Manager API path — Suricata rule: alert http any any -> $SDWAN_MGR 443 (msg:"CVE-2026-76504 hex encoded URI auth bypass"; content:"%25"; http_uri; sid:2026765040; rev:1;).
  • IAM / least privilege: Ensure API clients operate with the minimum required permissions; where the platform supports it, enforce mutual TLS (client certificates) for admin API endpoints as an additional authentication layer.
  • Configuration hardening: Enable the "Restrict Management Access" feature in SD-WAN Manager and disable any API endpoints not required for operations; follow the Cisco SD-WAN Manager hardening guide as a baseline.
  • Temporary service isolation: If patching cannot be completed immediately, take the SD-WAN Manager API service offline or restrict access to a single monitored jump host until a maintenance window can be scheduled.

Runbook · Step 3

Detection rules

  • Web server access logs: Look for requests to SD-WAN Manager API paths containing hex-encoded characters that return HTTP 200 from non-allowlisted source IPs — SPL: index=proxy uri_path="/api/*" uri_path="*%*" status=200 | where NOT src_ip IN (allowlist).
  • Sigma rule (network proxy): title: CVE-2026-76504 SD-WAN Manager Auth Bypass — match cs-uri-stem|contains: '/api/' AND cs-uri-stem|re: '%[0-9A-Fa-f]{2}' AND sc-status: 200 AND cs-username: '-' (unauthenticated request succeeding).
  • SIEM correlation: Alert on admin-level API actions (user creation, configuration changes, certificate export) occurring within 5 minutes of a hex-encoded URI request from the same source IP — classify as High severity.
  • Network telemetry (Zeek/Suricata): Monitor Zeek HTTP logs for uri fields containing %25 or double-encoded sequences on port 443 destined for the SD-WAN Manager; pair with Suricata SID 2026765040 above for layered coverage.
  • EDR/endpoint: On the SD-WAN Manager host, monitor for unexpected process spawns by the API/web server process (e.g. shell children of the web server process) as a post-exploitation indicator — Sysmon EID 1 with ParentImage matching the SD-WAN web server binary and Image in /bin/sh, bash, or equivalent.

Description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

ciscocatalyst_sd-wan_manager
20.12 – 20.12.8.220.15 – 20.15.6.120.18 – 20.18.4.126.1 – 26.1.2.120.9.10.1fixed from 20.9.10.1

Metrics

9.8
Source: nvd-v3
78.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
1.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-09-30 13:17 UTC
CWE-177

Weakness classes (CWE)

  • CWE-177Variant

    Improper Handling of URL Encoding (Hex Encoding)

    The product does not properly handle when all or part of an input has been URL encoded.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-03 00:16 UTC· psirt@cisco.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/76xxx/CVE-2026-76504.json">CVE-2026-76504</a>
  2. CVE Modified2026-10-01 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-76504","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
    • SSVC: {"id":"CVE-2026-76504","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
  3. Initial Analysis2026-09-30 22:28 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions up to (excluding) 20.9.10.1 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions from (including) 20.12 up to (excluding) 20.12.8.2 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions from (including) 20.15 up to (excluding) 20.15.6.1 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions from (including) 20.18 up to (excluding) 20.18.4.1 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions from (including) 26.1 up to (excluding) 26.1.2.1 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:26.2:*:*:*:*:*:*:*
    • Reference Type: Cisco Systems, Inc.: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU Types: Mitigation, Vendor Advisory
    • Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504 Types: US Government Resource
  4. CVE CISA KEV Update2026-09-30 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-09-30
    • Due Date: 2026-09-30
    • Required Action: 2026-09-30
    • Vulnerability Name: 2026-09-30
  5. CVE Modified2026-09-30 18:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504
    • SSVC: {"id":"CVE-2026-76504","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…

Linked advisories