Cisco warned customers on Wednesday that attackers are actively exploiting a critical zero-day vulnerability in the Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. The vulnerability, tracked as CVE-2026-76504, affects all deployments regardless of configuration and allows unauthenticated attackers to access affected systems remotely with admin privileges.
The flaw lies in API session-based authentication management, specifically improper handling of URI encoding in HTTP requests. According to Cisco, an attacker can bypass an authentication rule intended to restrict access to a particular API endpoint by sending a crafted HTTP request containing the URI-encoded character "%6a" (representing "j").
Cisco did not elaborate on the attacks but provided indicators of compromise. It advised administrators investigating potentially compromised systems to check the "serviceproxy-access.log" file (located at /var/log/nms/containers/service-proxy) and the "vmanage-server.log" file (at /var/log/nms/) for entries related to "j_security_check" from unknown or unauthorized IP addresses.
"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company said in a security advisory. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."
Fixed releases are available for versions 20.9, 20.12, 20.15, 20.18, 26.1, and 26.2, with specific patch versions listed in the advisory. Customers running earlier releases are advised to migrate to a fixed release.
CVE-2026-76504 is the fifth SD-WAN zero-day actively exploited in the wild since the start of 2026. In February, Cisco patched a critical information disclosure flaw (CVE-2026-20127) in SD-WAN Manager that had been exploited since at least 2023. Another maximum-severity authentication bypass flaw in the Catalyst SD-WAN Controller was also tagged as actively exploited earlier this year.