THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog after reports of active exploitation. The flaw, tracked as CVE-2026-76504, carries a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to assume the privileges of the admin user on an affected system.
CISA describes the issue as a hex encoding vulnerability in the handling of URI encoding within an HTTP request, which could enable an attacker to bypass authentication by sending a crafted request to the system’s API.
Cisco has stated it is aware of ongoing exploitation and has provided indicators of compromise (IoCs) for customers to assess impact. The IoCs point to specific log entries: audit lines in “/var/log/nms/containers/service-proxy/serviceproxy-access[.]log” showing access from unknown or unauthorized IPs, and entries in “/var/log/nms/vmanage-server[.]log” related to j_security_check calls, particularly for users named with the prefix “viptela-reserved-”.
Cisco has not disclosed details about the exploitation campaigns, perpetrators, or the extent of compromise. Federal Civilian Executive Branch (FCEB) agencies have until 3 October 2026 to apply fixes. Organisations using Catalyst SD-WAN Manager are urged to upgrade to the fixed release and follow vendor guidance to hunt for POST requests to URL-encoded variants of /j_security_check and review for signs of exploitation.