CVE-2026-76504
catalyst_sd-wan_manager: Improper Handling of URL Encoding (Hex Encoding) (CVE-2026-76504)
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-76504 scores CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning it is network-exploitable with no credentials, no user interaction, and low attack complexity — placing it in the highest urgency tier for any organisation running Cisco Catalyst SD-WAN Manager. The SD-WAN Manager is the centralised control plane for WAN fabric; admin-level API access allows an attacker to rewrite routing policies, manipulate VPN tunnels, and export device certificates, effectively owning the entire SD-WAN overlay. NIS2-scoped organisations with SD-WAN connecting critical sites or OT-adjacent networks should treat this as P1 regardless of whether the manager is directly internet-facing — reachability from a DMZ or a compromised internal host is sufficient for exploitation. Although CISA has not flagged known ransomware campaign use at the time of KEV listing, the authentication-bypass primitive is highly attractive for initial access brokers and supply-chain-style attacks against managed WAN infrastructure.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch: Cisco has released a fix for CVE-2026-76504 — upgrade all affected Cisco Catalyst SD-WAN Manager instances to the patched version immediately (consult the Cisco Security Advisory for the exact build number, as no specific version string is available in the current context).
- Restrict API exposure: Ensure the SD-WAN Manager API (TCP 443, TCP 8443) is not reachable from the internet or untrusted network segments — enforce firewall rules to limit access to a dedicated out-of-band management network or VPN-only access.
- Invalidate all active API sessions and rotate credentials: Terminate all current API sessions on the SD-WAN Manager and rotate admin credentials (local accounts and any TACACS+/RADIUS shared secrets), as an attacker with admin-level access may have created persistent backdoor accounts.
- Enforce IP allowlisting: Restrict SD-WAN Manager API access to a defined set of authorised management hosts via ACLs on upstream firewalls or the SD-WAN Manager's built-in access control filter.
- Preserve and forward logs: Confirm that HTTP access logs and API audit logs are being forwarded to your SIEM before any forensic evidence is overwritten by log rotation.
Runbook · Step 2
Mitigation layers
- Network segmentation: Place the SD-WAN Manager management interface (TCP 443/8443) exclusively on a dedicated management VLAN with no direct internet or production-VLAN reachability.
- WAF/IPS rule: Block or alert on HTTP requests containing hex-encoded URI sequences (e.g.
%2F,%2E, double-encoded%25xxpatterns) targeting the SD-WAN Manager API path — Suricata rule:alert http any any -> $SDWAN_MGR 443 (msg:"CVE-2026-76504 hex encoded URI auth bypass"; content:"%25"; http_uri; sid:2026765040; rev:1;). - IAM / least privilege: Ensure API clients operate with the minimum required permissions; where the platform supports it, enforce mutual TLS (client certificates) for admin API endpoints as an additional authentication layer.
- Configuration hardening: Enable the "Restrict Management Access" feature in SD-WAN Manager and disable any API endpoints not required for operations; follow the Cisco SD-WAN Manager hardening guide as a baseline.
- Temporary service isolation: If patching cannot be completed immediately, take the SD-WAN Manager API service offline or restrict access to a single monitored jump host until a maintenance window can be scheduled.
Runbook · Step 3
Detection rules
- Web server access logs: Look for requests to SD-WAN Manager API paths containing hex-encoded characters that return HTTP 200 from non-allowlisted source IPs — SPL:
index=proxy uri_path="/api/*" uri_path="*%*" status=200 | where NOT src_ip IN (allowlist). - Sigma rule (network proxy):
title: CVE-2026-76504 SD-WAN Manager Auth Bypass— matchcs-uri-stem|contains: '/api/'ANDcs-uri-stem|re: '%[0-9A-Fa-f]{2}'ANDsc-status: 200ANDcs-username: '-'(unauthenticated request succeeding). - SIEM correlation: Alert on admin-level API actions (user creation, configuration changes, certificate export) occurring within 5 minutes of a hex-encoded URI request from the same source IP — classify as High severity.
- Network telemetry (Zeek/Suricata): Monitor Zeek HTTP logs for
urifields containing%25or double-encoded sequences on port 443 destined for the SD-WAN Manager; pair with Suricata SID 2026765040 above for layered coverage. - EDR/endpoint: On the SD-WAN Manager host, monitor for unexpected process spawns by the API/web server process (e.g. shell children of the web server process) as a post-exploitation indicator — Sysmon EID 1 with
ParentImagematching the SD-WAN web server binary andImagein/bin/sh,bash, or equivalent.
Description
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
20.12 – 20.12.8.220.15 – 20.15.6.120.18 – 20.18.4.126.1 – 26.1.2.120.9.10.1fixed from 20.9.10.1Metrics
Show all metrics
Weakness classes (CWE)
CWE-177Variant
Improper Handling of URL Encoding (Hex Encoding)
The product does not properly handle when all or part of an input has been URL encoded.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-03 00:16 UTC· psirt@cisco.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/76xxx/CVE-2026-76504.json">CVE-2026-76504</a>
- CVE Modified2026-10-01 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-76504","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- SSVC: {"id":"CVE-2026-76504","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- Initial Analysis2026-09-30 22:28 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions up to (excluding) 20.9.10.1 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions from (including) 20.12 up to (excluding) 20.12.8.2 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions from (including) 20.15 up to (excluding) 20.15.6.1 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions from (including) 20.18 up to (excluding) 20.18.4.1 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* versions from (including) 26.1 up to (excluding) 26.1.2.1 *cpe:2.3:a:cisco:catalyst_sd-wan_manager:26.2:*:*:*:*:*:*:*
- Reference Type: Cisco Systems, Inc.: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU Types: Mitigation, Vendor Advisory
- Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504 Types: US Government Resource
- CVE CISA KEV Update2026-09-30 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-09-30
- Due Date: 2026-09-30
- Required Action: 2026-09-30
- Vulnerability Name: 2026-09-30
- CVE Modified2026-09-30 18:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504
- SSVC: {"id":"CVE-2026-76504","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
Linked advisories
- csoonline2026-10-01 13:36 UTCCisco SD-WAN Manager hit by zero-day admin access attack
- thehackernews2026-10-01 10:33 UTCCISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
- cert-fr2026-10-01 00:00 UTCVulnérabilité dans Cisco Catalyst SD-WAN (01 octobre 2026)
- thehackernews2026-09-30 15:24 UTCCisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- bleepingcomputer2026-09-30 14:46 UTCCisco warns of new SD-WAN zero-day exploited in attacks
- cisco-psirtCisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability