Executive Summary
Facts Only
* The vulnerability is CVE-2026-76504.
* It affects Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.
* The flaw involves improper handling of URI encoding in API session-based authentication management.
* It allows an unauthenticated remote attacker to bypass authentication rules.
* Successful exploitation grants administrative access with netadmin privileges.
* Cisco confirmed active exploitation in September 2026.
* The vulnerability is classified as CWE-177 (Improper Handling of URL Encoding).
* Indicators include specific URI encoding patterns like %6asecuritycheck for the authentication endpoint.
* Log artifacts to examine are /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log.
* Remediation involves upgrading to fixed software releases listed by Cisco (e.g., 20.9.10.1, 26.1.2.1).
Full Take
From the original · SOC Prime Research
Cisco has disclosed another actively exploited zero-day vulnerability affecting its Catalyst SD-WAN infrastructure. The latest flaw, tracked as CVE-2026-76504, is a critical authentication bypass in Cisco Catalyst SD-WAN Manager that could enable an unauthenticated remote attacker to gain administrative access to an affected system.Read the full story at socprime.com
Sentinel — Human
This text reads like professional, technically informed security journalism or an official advisory, successfully synthesizing complex technical details and strategic recommendations.
