<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-765-gk23zjcpx" -->

---
title: Critical Cisco Catalyst SD-WAN Manager API...
description: Cisco published a security advisory for CVE-2026-76504, a critical (CVSS 9.8) API authentication bypass affecting Cisco Catalyst SD-WAN Manager, caused by...
canonical: https://daily.dev/posts/critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-765-gk23zjcpx
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504) | daily.dev
og:description: Cisco published a security advisory for CVE-2026-76504, a critical (CVSS 9.8) API authentication bypass affecting Cisco Catalyst SD-WAN Manager, caused by...
og:url: https://daily.dev/posts/critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-765-gk23zjcpx
og:image: https://api.daily.dev/og/posts/gk23ZjcPx.png
og:image:alt: Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

**[Rapid7 Cybersecurity Blog](https://daily.dev/sources/rapid7-blog)** · 3 min read · 0 upvotes · 0 comments

## Summary

Cisco published a security advisory for CVE-2026-76504, a critical (CVSS 9.8) API authentication bypass affecting Cisco Catalyst SD-WAN Manager, caused by improper URL encoding handling. An unauthenticated attacker can craft an HTTP request to bypass an authentication rule on a specific API endpoint and gain admin-level API access. Cisco confirms active exploitation in the wild since September 2026. No workaround exists, but fixed releases are available across multiple version branches (e.g., 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1). Organizations are urged to patch on an emergency basis, restrict internet exposure, and audit for compromise using indicators such as encoded characters in j_security_check requests.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504>

## Questions this post answers

### What is CVE-2026-76504 and how does the Cisco Catalyst SD-WAN Manager authentication bypass work?

CVE-2026-76504 is a critical (CVSS 9.8) API authentication bypass in Cisco Catalyst SD-WAN Manager caused by improper URL encoding handling (CWE-177). An unauthenticated remote attacker sends a crafted HTTP request, such as encoding a single character in the j_security_check path, to bypass an authentication rule and gain API access with admin privileges. It affects the product regardless of configuration and is being actively exploited.

_Teams running Cisco SD-WAN Manager can track emerging exploited CVEs like this one on daily.dev to patch before attackers strike._

### Which Cisco Catalyst SD-WAN Manager versions fix CVE-2026-76504?

Fixed releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1; systems earlier than 20.9 must migrate to a fixed release. The cloud-based Cisco SD-WAN Cloud (Cisco Managed) service was already patched in release 20.15.605, with no customer action required for that offering. There is no workaround, so emergency upgrading outside normal patch cycles is recommended.

_Anyone planning an emergency SD-WAN Manager upgrade can follow version-specific fixes like these via daily.dev._

### How can I detect if my Cisco SD-WAN Manager was compromised via the j_security_check authentication bypass?

Check /var/log/nms/containers/service-proxy/serviceproxy-access.log for requests with an encoded character in the j_security_check path, such as POST /%6a_security_check HTTP/1.1, and check /var/log/nms/vmanage-server.log for requests tied to usernames beginning with viptela-reserved-. Any single character can be encoded by an attacker, and these log patterns should be weighed against normal network activity since they can occur during legitimate operations too.

_Security teams hunting for exploitation evidence can keep tabs on new indicators of compromise through daily.dev._

## Similar posts on daily.dev

- [Attackers exploiting unpatched Cisco SD-WAN flaw](https://daily.dev/posts/attackers-exploiting-unpatched-cisco-sd-wan-flaw-flftxgm0p) · CSO Online · 0 upvotes · 0 comments
- [More Cisco SD-WAN bugs battered in attacks](https://daily.dev/posts/more-cisco-sd-wan-bugs-battered-in-attacks-7hqpntonn) · The Register · 0 upvotes · 0 comments
- [Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks](https://daily.dev/posts/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks-haaubkuic) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#networking](https://daily.dev/tags/networking), [#cisco](https://daily.dev/tags/cisco)

[View this post on daily.dev](https://daily.dev/posts/critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-765-gk23zjcpx)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)","url":"https://daily.dev/posts/critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-765-gk23zjcpx","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-765-gk23zjcpx"},"datePublished":"2026-09-30T15:16:59.887Z","dateModified":"2026-10-01T13:58:21.894Z","description":"Cisco published a security advisory for CVE-2026-76504, a critical (CVSS 9.8) API authentication bypass affecting Cisco Catalyst SD-WAN Manager, caused by...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/403310fc83643451d0e643aaed18bd42?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/403310fc83643451d0e643aaed18bd42?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Rapid7 Cybersecurity Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Rapid7 Cybersecurity Blog","logo":"https://media.daily.dev/image/upload/logos/placeholder.jpg","url":"https://daily.dev/sources/rapid7-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-765-gk23zjcpx","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,networking,cisco","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Rapid7 Cybersecurity Blog","item":"https://daily.dev/sources/rapid7-blog"},{"@type":"ListItem","position":3,"name":"Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-765-gk23zjcpx#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-76504 and how does the Cisco Catalyst SD-WAN Manager authentication bypass work?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-76504 is a critical (CVSS 9.8) API authentication bypass in Cisco Catalyst SD-WAN Manager caused by improper URL encoding handling (CWE-177). An unauthenticated remote attacker sends a crafted HTTP request, such as encoding a single character in the j_security_check path, to bypass an authentication rule and gain API access with admin privileges. It affects the product regardless of configuration and is being actively exploited. Teams running Cisco SD-WAN Manager can track emerging exploited CVEs like this one on daily.dev to patch before attackers strike."}},{"@type":"Question","name":"Which Cisco Catalyst SD-WAN Manager versions fix CVE-2026-76504?","acceptedAnswer":{"@type":"Answer","text":"Fixed releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1; systems earlier than 20.9 must migrate to a fixed release. The cloud-based Cisco SD-WAN Cloud (Cisco Managed) service was already patched in release 20.15.605, with no customer action required for that offering. There is no workaround, so emergency upgrading outside normal patch cycles is recommended. Anyone planning an emergency SD-WAN Manager upgrade can follow version-specific fixes like these via daily.dev."}},{"@type":"Question","name":"How can I detect if my Cisco SD-WAN Manager was compromised via the j_security_check authentication bypass?","acceptedAnswer":{"@type":"Answer","text":"Check /var/log/nms/containers/service-proxy/serviceproxy-access.log for requests with an encoded character in the j_security_check path, such as POST /%6a_security_check HTTP/1.1, and check /var/log/nms/vmanage-server.log for requests tied to usernames beginning with viptela-reserved-. Any single character can be encoded by an attacker, and these log patterns should be weighed against normal network activity since they can occur during legitimate operations too. Security teams hunting for exploitation evidence can keep tabs on new indicators of compromise through daily.dev."}}]}
```

