Federal agencies have until Oct. 3 to remediate CVE-2026-76504 after Cisco confirmed unauthenticated admin access in active attacks.
The Cybersecurity and Infrastructure Security Agency on Wednesday added one vulnerability to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation.
The listing is CVE-2026-76504. CISA named it a Cisco Catalyst SD-WAN Manager hex encoding vulnerability. Federal Civilian Executive Branch agencies now face an Oct. 3 remediation date under Binding Operational Directive 26-04.
CISA put the risk in a single line: “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.”
Cisco published a critical advisory the same day. A flaw in API session-based authentication management can let an unauthenticated, remote attacker reach an affected system with the privileges of the admin user, the company said. Cisco scored the issue 9.8 under CVSS v3.1 and mapped it to CWE-177. The tracking bug is CSCww79570.
The cause is narrow. Improper handling of URI encoding in an HTTP request lets that request bypass an authentication rule meant to restrict a specific API endpoint. An attacker sends a crafted request to the API. A successful exploit yields API access as the admin user.
The bug affects Cisco Catalyst SD-WAN Manager regardless of system configuration. There is no toggle that shuts the exposure off. The product, previously sold as SD-WAN vManage, is the management console for the SD-WAN fabric.
Cisco’s Product Security Incident Response Team did not treat this as a paper finding. “In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,” the advisory said. “Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.”
No workaround fixes it. Cisco said so directly: “There are no workarounds that address this vulnerability.” On-premises operators can still cut exposure by keeping the manager off unsecured networks, including the internet, and by allowing only known, trusted hosts through a filtering device such as a firewall. That restriction is already deployed in Cisco-managed cloud-hosted environments.
Fixed releases run by software train. Builds earlier than 20.9 must migrate to a patched release. First fixed versions are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Cisco also addressed the flaw in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605. For those cloud customers, no user action is required.
CISA’s catalog row tracks the vendor account. Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Known ransomware campaign use is listed as unknown.
The required federal action is specific. Apply mitigations in accordance with vendor instructions. Comply with BOD 26-04 and CISA’s forensics triage requirements. Follow the directive’s cloud-service rules, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset’s internet exposure and meet the patching guidelines.
BOD 26-04, issued June 10, binds FCEB agencies. It tells them to prioritize rapid remediation of high-risk KEV listings on publicly exposed assets that grant total control after exploitation, and to check whether threat actors compromised the system before the patch was applied. The order does not cover private firms. CISA still encouraged all organizations to adopt risk-based vulnerability management and put KEV items first.
Internet-facing managers sit at the front of that list. Cisco warned that systems with ports exposed to the internet are at risk of compromise. Sample indicators use %6a as a URI-encoded “j” in a request. That string is only an example. Any single encoded character can trigger the same bypass.
Operators should review /var/log/nms/containers/service-proxy/serviceproxy-access.log for j_security_check traffic from unknown or unauthorized addresses. They should also review /var/log/nms/vmanage-server.log for the same path, especially calls tied to usernames that start with viptela-reserved-. Cisco noted those strings can appear during standard operations. Measure them against normal traffic.
Customers who need help determining compromise may open a Severity 3 case with Cisco’s Technical Assistance Center and put CVE-2026-76504 in the title. Collect an admin-tech file first with the request admin-tech command so TAC has a file to review.
CISA said it will keep adding catalog entries that meet its criteria. Potential additions need a CVE identifier, evidence of exploitation, and clear mitigation guidance. Anyone who sees an exploited flaw still missing from the list can file it through the KEV Nomination Form.
Links for copy/paste

