{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cisco-sd-wan-cloud--20.15.605/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*","cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.12.6:*:*:*:*:*:*:*","cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:*:*:*:*:*:*:*:*","cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:20.12.6:*:*:*:*:*:*:*","cpe:2.3:a:cisco:sd-wan_vsmart_controller:*:*:*:*:*:*:*:*","cpe:2.3:a:cisco:sd-wan_vsmart_controller:20.12.6:*:*:*:*:*:*:*","cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.12.7:*:*:*:*:*:*:*","cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:20.12.7:*:*:*:*:*:*:*","cpe:2.3:a:cisco:sd-wan_vsmart_controller:20.12.7:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-76504"},{"cvss":10,"id":"CVE-2026-20127"},{"cvss":10,"id":"CVE-2026-20182"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Catalyst SD-WAN Manager","Cisco SD-WAN Cloud (\u003c 20.15.605)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","cisco","sdwan","authentication-bypass"],"_cs_type":"threat","_cs_vendors":["Cisco"],"content_html":"\u003cp\u003eCisco has disclosed a critical authentication bypass vulnerability, identified as CVE-2026-76504, affecting Cisco Catalyst SD-WAN Manager. The flaw stems from improper handling of URL encoding (CWE-177) within API authentication logic. An unauthenticated, remote attacker can leverage this weakness to bypass authentication rules by sending crafted HTTP requests to specific API endpoints, granting them unauthorized access with administrative privileges.\u003c/p\u003e\n\u003cp\u003eCisco PSIRT has confirmed that this vulnerability is being actively exploited in the wild as of September 2026. This follows other significant authentication bypass flaws discovered in the Catalyst SD-WAN networking stack earlier in the year (CVE-2026-20127 and CVE-2026-20182). Given the critical nature of the flaw and confirmed in-the-wild exploitation, organizations must treat this as an emergency remediation event. There are no workarounds, and all internet-facing instances are at high risk of compromise. Immediate application of vendor-supplied patches is required to secure the control plane.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing Cisco Catalyst SD-WAN Manager instances.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the j_security_check API endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker applies URI encoding to one or more characters within the request path (e.g., %6a instead of j) to bypass static authentication filters.\u003c/li\u003e\n\u003cli\u003eThe SD-WAN Manager improperly processes the encoded URL, incorrectly validating the request as authenticated.\u003c/li\u003e\n\u003cli\u003eAttacker gains session access with the privileges of the admin user.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the administrative session to perform unauthorized configuration changes or exfiltration.\u003c/li\u003e\n\u003cli\u003eAttacker maintains persistence or executes further commands via the compromised management interface.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to gain administrative access to the Cisco Catalyst SD-WAN Manager. This impact is severe, potentially resulting in full compromise of the SD-WAN controller, unauthorized access to sensitive network configuration data, or the ability to manipulate global routing and traffic flow across the managed SD-WAN network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all on-premises instances of Cisco Catalyst SD-WAN Manager to the fixed releases specified in the Cisco security advisory (e.g., 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1).\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for exploitation attempts targeting the j_security_check endpoint.\u003c/li\u003e\n\u003cli\u003eAudit logs located at /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for indicators of anomalous j_security_check access or unexpected usernames prefixed with 'viptela-reserved-'.\u003c/li\u003e\n\u003cli\u003eRestrict access to the SD-WAN management interface to trusted internal IP addresses and protect control components behind network filtering devices.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T19:39:20Z","date_published":"2026-09-30T16:33:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cisco-sdwan-auth-bypass/","summary":"Attackers are actively exploiting an unauthenticated API authentication bypass vulnerability (CVE-2026-76504) in Cisco Catalyst SD-WAN Manager to gain administrative control via URL-encoded HTTP requests.","title":"Active Exploitation of Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)","url":"https://feed.craftedsignal.io/briefs/2026-09-cisco-sdwan-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cisco SD-WAN Cloud (\u003c 20.15.605)","version":"https://jsonfeed.org/version/1.1"}