<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cisco SD-WAN Cloud (&lt; 20.15.605) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/cisco-sd-wan-cloud--20.15.605/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:33:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/cisco-sd-wan-cloud--20.15.605/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Active Exploitation of Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cisco-sdwan-auth-bypass/</link><pubDate>Wed, 30 Sep 2026 16:33:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cisco-sdwan-auth-bypass/</guid><description>Attackers are actively exploiting an unauthenticated API authentication bypass vulnerability (CVE-2026-76504) in Cisco Catalyst SD-WAN Manager to gain administrative control via URL-encoded HTTP requests.</description><content:encoded><![CDATA[<p>Cisco has disclosed a critical authentication bypass vulnerability, identified as CVE-2026-76504, affecting Cisco Catalyst SD-WAN Manager. The flaw stems from improper handling of URL encoding (CWE-177) within API authentication logic. An unauthenticated, remote attacker can leverage this weakness to bypass authentication rules by sending crafted HTTP requests to specific API endpoints, granting them unauthorized access with administrative privileges.</p>
<p>Cisco PSIRT has confirmed that this vulnerability is being actively exploited in the wild as of September 2026. This follows other significant authentication bypass flaws discovered in the Catalyst SD-WAN networking stack earlier in the year (CVE-2026-20127 and CVE-2026-20182). Given the critical nature of the flaw and confirmed in-the-wild exploitation, organizations must treat this as an emergency remediation event. There are no workarounds, and all internet-facing instances are at high risk of compromise. Immediate application of vendor-supplied patches is required to secure the control plane.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify internet-facing Cisco Catalyst SD-WAN Manager instances.</li>
<li>Attacker crafts an HTTP request targeting the j_security_check API endpoint.</li>
<li>Attacker applies URI encoding to one or more characters within the request path (e.g., %6a instead of j) to bypass static authentication filters.</li>
<li>The SD-WAN Manager improperly processes the encoded URL, incorrectly validating the request as authenticated.</li>
<li>Attacker gains session access with the privileges of the admin user.</li>
<li>Attacker leverages the administrative session to perform unauthorized configuration changes or exfiltration.</li>
<li>Attacker maintains persistence or executes further commands via the compromised management interface.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated remote attacker to gain administrative access to the Cisco Catalyst SD-WAN Manager. This impact is severe, potentially resulting in full compromise of the SD-WAN controller, unauthorized access to sensitive network configuration data, or the ability to manipulate global routing and traffic flow across the managed SD-WAN network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade all on-premises instances of Cisco Catalyst SD-WAN Manager to the fixed releases specified in the Cisco security advisory (e.g., 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1).</li>
<li>Deploy the Sigma rules below to monitor for exploitation attempts targeting the j_security_check endpoint.</li>
<li>Audit logs located at /var/log/nms/containers/service-proxy/serviceproxy-access.log and /var/log/nms/vmanage-server.log for indicators of anomalous j_security_check access or unexpected usernames prefixed with 'viptela-reserved-'.</li>
<li>Restrict access to the SD-WAN management interface to trusted internal IP addresses and protect control components behind network filtering devices.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>cisco</category><category>sdwan</category><category>authentication-bypass</category></item></channel></rss>