Zero-Day Cisco SD-WAN CISA KEV

One encoded character opens the Cisco SD-WAN admin API

October 2, 2026·8 min read·Chris Boker, Founder, CVEasy AI
Cisco Catalyst SD-WAN Manager auth bypass driven by a single hex-encoded character in the j_security_check path

On September 30, 2026, Cisco PSIRT published advisory cisco-sa-sdwan-webauth-xr8beuuU for CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager carrying a CVSS 3.1 score of 9.8. CISA added it to the KEV catalog the same day with a federal remediation deadline of October 3, 2026, and Cisco confirmed in-the-wild exploitation. It is the fifth actively exploited SD-WAN zero-day of the year, and the whole chain is one hex-encoded letter in the URI.

The one request Cisco published

Cisco's advisory names the servlet path that normally authenticates administrators into Manager: j_security_check, the standard form-login endpoint from Java Servlet containers. An authentication filter sits in front of it so an unauthenticated caller never reaches a session that would carry admin rights, and in the vulnerable builds that filter matches literal paths. A request to POST /j_security_check engages the filter and gets rejected; the same request as POST /%6a_security_check, where %6a is the hex encoding of the letter j, slips past because the filter sees a path that does not match its rule. The dispatcher then percent-decodes the URI, resolves the same servlet, and executes the request as an authenticated administrator.

Cisco classifies the root cause as CWE-177, Improper Handling of URL Encoding and notes that %6a is one example. The attacker inherits admin privileges with no credentials, session cookie, or replay of a captured token.

Why %6a works and literal j does not

The filter that enforces the auth rule and the servlet that handles the request were built against different understandings of what a URI is. RFC 3986 says %6a and j are the same character after decoding, so a spec-compliant router treats them as the same resource; a string-matching filter that compares raw URI bytes against a literal rule treats them as different. Both can be true in the same application when the two components do not share a canonicalization step, which is the pattern behind HTTP request smuggling, reverse-proxy path confusion, Tomcat's own CVE-2012-3546, and the middleware auth bypasses James Kettle and watchTowr keep demonstrating against appliance after appliance.

Cisco has not published the filter chain in detail, but the shape is familiar from every Java web stack with a servlet-filter auth rule: an early filter runs on the raw request URI before HttpServletRequest.getPathInfo normalization, a later dispatcher runs after canonical decoding, and the window between those two readings is the vulnerability. The fix per the Cisco advisory is to canonicalize the URI before the filter decides and compare against the normalized form, which is the same answer every stack eventually arrives at. The Apache Tomcat hardening guide gives the same warning about reverse proxies and encoded slashes, moved one layer in.

What the admin API actually exposes

Catalyst SD-WAN Manager is the control plane for the overlay. Admin API access means policy push to every edge device, template changes, certificate operations, user management, and configuration of the IPsec and TLS fabric. An attacker who bypasses auth becomes a legitimate administrator from the perspective of every downstream vEdge and cEdge router, with the same signing material and session rights a human admin would hold. The right question is not whether the controller was accessed but what the controller did while it was accessed, because the branches have no way to verify a given template push came from a real human. A compromised Manager that reads its own secrets store, certificates, and CA material leaves footholds that outlast any single patch window, which is why the KEV deadline is 72 hours and not 21 days.

Why a CVSS-first queue mis-handles this one

CVSS puts CVE-2026-76504 at 9.8, which looks like a slam dunk for prioritization. The problem is that most mid-size triage queues already hold dozens of CVSS 9.8 entries this week, including the FortiMail path traversal CVE-2026-104286 that CISA added to KEV the same day. CVSS alone does not tell you which is your emergency, and a version-matching scanner only answers whether the component is present at a vulnerable version. It cannot tell you whether that Manager instance is reachable from the internet, whether a management ACL has been applied, whether the appliance is behind a bastion, or whether a honey instance is already catching encoded j_security_check probes. Treating 9.8 as the current reality pulls three engineers off a real incident to patch an appliance that was never reachable in the first place, while an exposed lab tenant stays red for another 48 hours.

How TRIS layers it for your inventory

TRIS, the Threat and Risk Intelligence Scoring engine inside CVEasy AI, scores each finding against the inventory it already holds for your environment rather than a generic worst case. Four layers decide where CVE-2026-76504 lands.

Exploitation status. Cisco PSIRT confirms active exploitation and CISA added the CVE to KEV on September 30 with a federal deadline of October 3; both pin this layer at its top band. Proof of in-the-wild activity is stronger evidence than a public PoC, and TRIS weighs the two differently where other feeds collapse them.

Reachability. Is the Manager admin UI bound to an interface reachable from an untrusted network? An internet-exposed instance sits in the top ACT band, while a Manager reachable only from a dedicated management VRF behind a jump host drops several bands even with the same CVE, and a patched instance drops out of the queue entirely. CVSS does not change across those three cases; TRIS does, because the signal that moves is the one TRIS is built to measure.

Blast radius. This is the SD-WAN control plane; if the controller falls, every branch and campus edge it manages becomes an attacker-shaped surface. TRIS reads your topology, counts the downstream devices under this controller, and raises the finding when the blast radius is wide and the recovery path is slow. A lab controller with two spokes scores lower than production with 400.

Compensating controls. Management-plane ACLs, zero-trust gateways in front of Manager, and WAF rules that normalize URIs before forwarding each shift the time an attacker needs and the probability of detection. None neutralize the bug, so TRIS treats them as mitigations rather than fixes.

The outcome is that the same CVE lands at different priorities on different inventories: a hardened, patched, management-plane-only deployment is a Thursday-afternoon ticket, while an unpatched, internet-exposed Manager with 400 spokes is a call-the-on-call-network-engineer fire. CVSS cannot tell you which is which; TRIS does, from the inventory on your own hardware, without sending any of it to a cloud multi-tenant.

Patch, hunt, rotate

Cisco's patch path is an upgrade to one of the fixed releases: 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, or 20.9.10.1. Anything on the 20.6, 20.7, or 20.8 trains has no in-place fix and needs migration to a supported branch. No workaround fully addresses the bug, so a management-plane ACL and a WAF rule in front of Manager are stopgaps, not fixes.

For hunting, Cisco points at /var/log/nms/vmanage-server.log. Look for requests to j_security_check or any encoded variant, especially from external IPs. The strongest published IOC is activity on that endpoint associated with usernames beginning viptela-reserved-, which are system service accounts that should never authenticate through the external login form; any such hit from an unexpected source address is worth escalating as a presumed compromise. A reasonable access-log regex is %[0-9a-fA-F]{2}_security_check.

If an instance was reachable and shows those indicators, treat it as compromised and rotate everything the controller touched: SSH and TACACS credentials, controller certificates and their CA material, API tokens issued by Manager, and SNMP community strings. Re-templating the fleet from a known-good configuration is cheaper than finding out six weeks later that a policy change you did not make is still in place on a branch router.

72 hours is the deadline, not the hunt window. CISA set October 3, 2026 as the remediation deadline. Your hunt window is the entire time the appliance was internet-reachable before the patch landed. An attacker who used the bypass before you closed it does not go away because you upgraded the binary.

How CVEasy AI surfaces this

CVEasy AI is the number one local-first Continuous Threat Exposure Management platform. It ingests Cisco PSIRT, CISA KEV, NVD, and researcher write-ups, runs them through TRIS against the inventory on your own hardware, and answers the question that decides your week: which Manager instance is in the fire, in what order, and what rotates when it comes back up. Your inventory, topology, and logs stay on your infrastructure.

The sentence that matters. CVSS 9.8 told you this was urgent. It did not tell you which of your controllers was reachable, which was patched, or which one had a viptela-reserved- login from an address outside your allow list at 03:14 UTC. TRIS answers that against your inventory, on your hardware.

Sources: BleepingComputer, Help Net Security, SecurityWeek, Cyber Security News, The Hacker News, Rapid7, Horizon3, SOC Prime, Cisco PSIRT advisory cisco-sa-sdwan-webauth-xr8beuuU, CISA KEV catalog

Which of your Catalyst SD-WAN controllers is actually in the fire?

CVEasy AI ranks CVE-2026-76504 against your inventory, your topology, and your management-plane posture, on your hardware. The CVSS 9.8 is the ceiling; TRIS tells you which instance you touch first.

Related Reading