CVSSv3.1 severity score: 9.8 (Source: Rapid7 (September 30, 2026))
A login check can fail without being broken. One pattern behind this kind of flaw is that a check and the system behind it read the same request differently. A new flaw in Cisco Catalyst SD-WAN Manager may fit that pattern.
Rapid7's report says the flaw results from improper handling of URL encoding (CWE-177), which points that way. Rapid7's summary does not say how Cisco's rule reads the path. So this is our interpretation, not a finding.
The people who carry this risk are the network team and the on-call engineer. They must weigh an emergency change against the normal patch schedule.
What Cisco and Rapid7 report
Cisco published an advisory on September 30, 2026 for CVE-2026-76504. It is an API authentication bypass. The flaw carries a CVSS v3.1 score of 9.8, as reported by Rapid7.
The attacker needs no account and can be anywhere on the internet. One crafted web request gets past the login rule for a specific API endpoint. The attacker then has the same access as the admin user.
Cisco says attackers are already using the flaw. Its security response team learned of the activity in September 2026. Any instance with ports open to the internet is at risk. No configuration setting avoids the flaw.
How the bypass works
A web address can write any character in an encoded form. The letter j, for example, can be written as %6a. Both forms mean the same thing to a browser.
Here, a request that spells a path in an unexpected way gets past the login rule. Think of a door guard with a list of names who does not recognise a nickname. That comparison is ours. The encoded request and the bypassed rule come from Rapid7's report.
Cisco's sample log entry is a request such as POST /%6a_security_check. Rapid7's summary does not explain how the rule reads the path internally. It states only the result: admin-level API access.
Why the attack is harder to spot than it looks
Cisco says %6a is only an example. An attacker can encode any single character in the request. A search for that one string would miss other spellings.
Cisco points teams to two logs. In serviceproxy-access.log, look for j_security_check requests with an encoded character in the path. In vmanage-server.log, look for j_security_check requests tied to usernames that start with viptela-reserved-.
Cisco adds a caution. These entries can also appear in normal operations. Results need comparing with the network's usual behaviour, so the review needs someone who knows what normal looks like.
A product with a history this year
Rapid7 notes two earlier flaws in SD-WAN Manager this year. Both let unauthenticated attackers bypass peering authentication. They are CVE-2026-20127 and CVE-2026-20182. Both sat in the vdaemon service and related networking code.
CVE-2026-76504 is a separate issue in an API authentication path. Even so, Rapid7 argues that repeated bypasses in internet-facing SD-WAN control parts reinforce the need for emergency fixes. That claim is about this product line, not the industry.
What to do and what to ask
Rapid7 advises moving to a fixed release ahead of the regular patch schedule. It also advises auditing internet-facing systems for signs of compromise. Cisco has released updates and its advisory carries the release details. There is no workaround.
Cisco offers a stopgap for on-premises customers: block access from unsecured networks. If internet access is required, limit it to known, trusted hosts. Put the control components behind a filtering device. Cisco says Cisco-hosted environments already have this. Rapid7 says to install the update even with the stopgap in place.
Leaders can put four questions to their teams:
1. Is any SD-WAN Manager instance reachable from the internet, and who approved that?
2. Which release does each instance run, and is it a fixed one?
3. Did anyone search both logs for encoded characters of any kind in the j_security_check path, rather than only the %6a example?
4. If we find suspicious entries, who opens the Cisco support case? Cisco says customers can open a Severity 3 TAC case with the CVE ID in the title and an admin-tech file.
Rapid7 says its vulnerability checks are expected in the October 1 content release.
Patch first. Then ask whether your other login rules read a request the same way as the systems they protect. This flaw may be an example, though the sources do not confirm the cause.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Rapid7.





