By Heath Callahan
Publication Date: 2026-10-02 18:42:00
Analysis
A single character substitution in a URL path circumvents authentication on the management API that controls entire SD-WAN fabrics. CISA’s deadline is tomorrow.
A critical authentication bypass vulnerability, tracked as CVE-2026-76504, is currently being exploited in the wild against Cisco Catalyst SD-WAN Manager. The vulnerability, which carries a CVSS score of 9.8, allows unauthenticated remote attackers to gain administrative access to the management API. This flaw stems from improper handling of URL/URI encoding, specifically within the j_security_check path.
The exploit mechanism is deceptively simple. By substituting the character ‘j’ with its URI-encoded equivalent, %6a, an attacker can bypass the authentication rules protecting the management API. This single-character manipulation effectively tricks the system into granting access without valid credentials. Because the SD-WAN Manager acts as a centralized control point for up to 6,000 devices, the compromise of…



