<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pedro Ribeiro Magalhães on Senthorus Blog</title><link>https://blog.senthorus.ch/author/pedro-ribeiro-magalh%C3%A3es/</link><description>Recent content in Pedro Ribeiro Magalhães on Senthorus Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 08 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.senthorus.ch/author/pedro-ribeiro-magalh%C3%A3es/index.xml" rel="self" type="application/rss+xml"/><item><title>Deep Dive: CVE-2026-76504, Authentication Bypass in Cisco Catalyst SD-WAN Manager</title><link>https://blog.senthorus.ch/posts/cve_2026_76504/</link><pubDate>Thu, 08 Oct 2026 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2026_76504/</guid><description>&lt;img src="https://blog.senthorus.ch/cve_2026_76504/cve_2026_76504_0.png" alt="Featured image of post Deep Dive: CVE-2026-76504, Authentication Bypass in Cisco Catalyst SD-WAN Manager" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>On &lt;strong>30 September 2026&lt;/strong>, Cisco published advisory &lt;code>cisco-sa-sdwan-webauth-xr8beuuU&lt;/code> for &lt;strong>CVE-2026-76504&lt;/strong>, a critical authentication bypass in &lt;strong>Cisco Catalyst SD-WAN Manager&lt;/strong> (formerly vManage). Cisco found the flaw while its Technical Assistance Center (TAC) was working on a customer support case. By then, attackers were already exploiting it. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog the same day and gave US federal agencies &lt;strong>three days&lt;/strong> to fix it.&lt;/p>
&lt;p>The bug sounds almost trivial: replace the letter &lt;code>j&lt;/code> with its URL-encoded form &lt;code>%6a&lt;/code> in the login path, and an authentication rule stops applying. The result is not trivial at all. The attacker gets access to the management API &lt;strong>as the built-in &lt;code>admin&lt;/code> user&lt;/strong>, which controls the configuration and policies of every router the Manager administers.&lt;/p>
&lt;p>For SOC teams, this is the latest of several exploited SD-WAN Manager flaws in 2026, and it needs both quick patching and a real investigation. This article explains how the vulnerability works, what is publicly known about its exploitation, and how to hunt for it and respond.&lt;/p>
&lt;p>&lt;em>This analysis reflects public information available on 8 October 2026.&lt;/em>&lt;/p>
&lt;h2 id="risk-snapshot">Risk Snapshot
&lt;/h2>&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Signal&lt;/th>
&lt;th>Assessment&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>🔴 &lt;strong>CVSS v3.1&lt;/strong>&lt;/td>
&lt;td>&lt;strong>9.8 / CRITICAL&lt;/strong> (&lt;code>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&lt;/code>)&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>🧬 &lt;strong>Weakness&lt;/strong>&lt;/td>
&lt;td>CWE-177, Improper Handling of URL Encoding&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>🎯 &lt;strong>Product&lt;/strong>&lt;/td>
&lt;td>Cisco Catalyst SD-WAN Manager, any configuration&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>🔓 &lt;strong>Auth Required&lt;/strong>&lt;/td>
&lt;td>None&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>👑 &lt;strong>Resulting Privilege&lt;/strong>&lt;/td>
&lt;td>Built-in &lt;code>admin&lt;/code> user (netadmin role) on the management API&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>⚠️ &lt;strong>Exploitation&lt;/strong>&lt;/td>
&lt;td>&lt;strong>In the Wild ✓&lt;/strong> (identified in September 2026)&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>📌 &lt;strong>KEV Listed&lt;/strong>&lt;/td>
&lt;td>30 September 2026, federal due date 3 October 2026&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>🛠️ &lt;strong>Workaround&lt;/strong>&lt;/td>
&lt;td>&lt;strong>None&lt;/strong>, upgrade required&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>☁️ &lt;strong>Cisco-managed cloud&lt;/strong>&lt;/td>
&lt;td>Already fixed (20.15.605), no customer action&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;h2 id="section-1-technical-overview-of-cve-2026-76504">Section 1: Technical Overview of CVE-2026-76504
&lt;/h2>&lt;h3 id="what-is-catalyst-sd-wan-manager">What is Catalyst SD-WAN Manager?
&lt;/h3>&lt;p>Catalyst SD-WAN Manager is the centralized management plane of Cisco&amp;rsquo;s SD-WAN solution, inherited from the Viptela acquisition. Administrators use its web interface and REST API to build device templates, define routing and security policies, and push them to the WAN Edge routers and control components across every site.&lt;/p>
&lt;p>That central role is what makes it such a valuable target. An attacker with admin access to the Manager does not compromise one device; they gain control over &lt;strong>routing policies, segmentation rules, device configurations and administrative accounts across the whole fabric&lt;/strong>.&lt;/p>
&lt;h3 id="the-vulnerability">The vulnerability
&lt;/h3>&lt;p>Cisco describes the root cause as follows:&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>&amp;ldquo;This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule.&amp;rdquo;&lt;/strong>&lt;br>
&lt;em>Cisco Security Advisory cisco-sa-sdwan-webauth-xr8beuuU&lt;/em>&lt;/p>&lt;/blockquote>
&lt;p>The flaw sits in the &lt;strong>session-based authentication of the management API&lt;/strong>. An unauthenticated, remote attacker sends a crafted HTTP request and gains access to the API &lt;strong>with the privileges of the &lt;code>admin&lt;/code> user&lt;/strong>. By default, that account holds the &lt;strong>netadmin&lt;/strong> role, which allows every operation. Cisco states that the Manager is affected &lt;strong>regardless of its configuration&lt;/strong>.&lt;/p>
&lt;p>Public analyses from Rapid7 and Horizon3.ai identify the target: &lt;code>j_security_check&lt;/code>, the form-login endpoint. The indicator shared publicly is a request in which the first letter is URL-encoded:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-http" data-lang="http">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#a6e22e">POST&lt;/span> /%6a_security_check &lt;span style="color:#66d9ef">HTTP&lt;/span>&lt;span style="color:#f92672">/&lt;/span>&lt;span style="color:#ae81ff">1.1&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>&lt;code>0x6a&lt;/code> is the ASCII code of &lt;code>j&lt;/code>. Once decoded, the path is the ordinary login endpoint. Before decoding, it is a string that the authentication rule apparently does not recognise.&lt;/p>
&lt;h3 id="why-does-one-encoded-letter-matter">Why does one encoded letter matter?
&lt;/h3>&lt;p>This is a classic case of &lt;strong>CWE-177&lt;/strong>: two parts of the same application read one path in two different ways. A security check is evaluated against the raw form of the URL. Another component then decodes or normalises the path before routing it. If the two disagree, a request can be &amp;ldquo;unknown&amp;rdquo; to the check and still reach the protected function.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2026_76504/cve_2026_76504_1.png"
loading="lazy"
alt="Simplified illustration: the encoded request is not matched by the authentication rule, is then normalised to /j_security_check and ends up with an admin API session"
>&lt;/p>
&lt;p>&lt;em>Figure 1. Conceptual illustration of the bug class. Cisco has not published implementation details; the exact internal components involved are not public.&lt;/em>&lt;/p>
&lt;p>One point is useful for detection. &lt;code>j_security_check&lt;/code> is the normal login path, so legitimate logins hit it all the time. However, according to &lt;a class="link" href="https://www.rfc-editor.org/rfc/rfc3986#section-2.3" target="_blank" rel="noopener"
>RFC 3986&lt;/a>, letters, digits and &lt;code>- . _ ~&lt;/code> are &lt;em>unreserved&lt;/em> characters that clients should not percent-encode. A browser or a regular API client has no reason to send &lt;code>%6a&lt;/code> instead of &lt;code>j&lt;/code>. &lt;strong>An encoded letter in a login path is therefore a much stronger signal than the login path alone.&lt;/strong>&lt;/p>
&lt;h3 id="affected-and-fixed-versions">Affected and fixed versions
&lt;/h3>&lt;table>
&lt;thead>
&lt;tr>
&lt;th style="text-align: center">Release train&lt;/th>
&lt;th style="text-align: center">First fixed release&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td style="text-align: center">Earlier than 20.9&lt;/td>
&lt;td style="text-align: center">Migrate to a fixed release&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">20.9&lt;/td>
&lt;td style="text-align: center">20.9.10.1&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">20.12&lt;/td>
&lt;td style="text-align: center">20.12.8.2&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">20.15&lt;/td>
&lt;td style="text-align: center">20.15.6.1&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">20.18&lt;/td>
&lt;td style="text-align: center">20.18.4.1&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">26.1&lt;/td>
&lt;td style="text-align: center">26.1.2.1&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">26.2&lt;/td>
&lt;td style="text-align: center">26.2.1&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">Cisco-managed cloud&lt;/td>
&lt;td style="text-align: center">20.15.605 (already deployed by Cisco)&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;p>Always confirm the target release against the latest revision of the Cisco advisory before scheduling the change. Fixed-release tables are sometimes updated after publication.&lt;/p>
&lt;h2 id="section-2-exploitation--threat-landscape">Section 2: Exploitation &amp;amp; Threat Landscape
&lt;/h2>&lt;h3 id="what-is-known">What is known
&lt;/h3>&lt;ul>
&lt;li>&lt;strong>Exploitation was observed before disclosure.&lt;/strong> Cisco identified in-the-wild exploitation in September 2026 while handling a TAC case. The investigation window therefore starts before 30 September, not on that date.&lt;/li>
&lt;li>&lt;strong>CISA set a three-day deadline.&lt;/strong> The KEV entry was added on 30 September with a remediation due date of 3 October 2026 for US federal civilian agencies. That is far shorter than the usual two weeks given for new KEV entries.&lt;/li>
&lt;li>&lt;strong>No verified public exploit, but the request is trivial.&lt;/strong> As of 1 October, SOCRadar reported no independently verified working exploit. Still, the indicator itself (&lt;code>/%6a_security_check&lt;/code>) is public, and rebuilding such a request takes minutes. Opportunistic scanning should be expected.&lt;/li>
&lt;li>&lt;strong>No public attribution.&lt;/strong> Cisco has not disclosed who is behind the activity, how many organisations are affected or what the attackers were after.&lt;/li>
&lt;/ul>
&lt;h3 id="a-product-under-sustained-pressure">A product under sustained pressure
&lt;/h3>&lt;p>CVE-2026-76504 is not an isolated case. SD-WAN Manager has been a recurring target throughout 2026:&lt;/p>
&lt;table>
&lt;thead>
&lt;tr>
&lt;th style="text-align: center">CVE&lt;/th>
&lt;th style="text-align: center">Disclosed&lt;/th>
&lt;th style="text-align: center">Type&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td style="text-align: center">CVE-2026-20127&lt;/td>
&lt;td style="text-align: center">February 2026&lt;/td>
&lt;td style="text-align: center">Authentication bypass (CVSS 10.0)&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">CVE-2026-20182&lt;/td>
&lt;td style="text-align: center">May 2026&lt;/td>
&lt;td style="text-align: center">Authentication bypass (CVSS 10.0)&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">CVE-2026-20245 / CVE-2026-20262&lt;/td>
&lt;td style="text-align: center">June 2026&lt;/td>
&lt;td style="text-align: center">Privilege escalation&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td style="text-align: center">&lt;strong>CVE-2026-76504&lt;/strong>&lt;/td>
&lt;td style="text-align: center">&lt;strong>September 2026&lt;/strong>&lt;/td>
&lt;td style="text-align: center">&lt;strong>Authentication bypass (CVSS 9.8)&lt;/strong>&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;p>According to The Hacker News, CISA&amp;rsquo;s KEV catalog listed &lt;strong>eight Cisco SD-WAN vulnerabilities for 2026&lt;/strong> as of 30 September.&lt;/p>
&lt;p>Earlier campaigns against this product were linked to &lt;strong>UAT-8616&lt;/strong>, a sophisticated actor active since at least 2023. Tenable summarises its post-compromise tradecraft: rogue account creation, SSH key injection, NETCONF manipulation, software downgrades to reach an older privilege escalation flaw (CVE-2022-20775) before restoring the original version, and log clearing.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>⚠ Attribution caution&lt;/strong>&lt;br>
There is &lt;strong>no public link&lt;/strong> between UAT-8616 and CVE-2026-76504. We use this tradecraft below only as a set of &lt;strong>hunting hypotheses&lt;/strong>, because it shows what an attacker with admin access to a Manager has done before.&lt;/p>&lt;/blockquote>
&lt;h2 id="section-3-soc-perspective-detection--hunting">Section 3: SOC Perspective, Detection &amp;amp; Hunting
&lt;/h2>&lt;h3 id="where-to-look">Where to look
&lt;/h3>&lt;p>Cisco&amp;rsquo;s advisory points to two log files on the Manager:&lt;/p>
&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Log file&lt;/th>
&lt;th>What to review&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>&lt;code>/var/log/nms/containers/service-proxy/serviceproxy-access.log&lt;/code>&lt;/td>
&lt;td>&lt;code>j_security_check&lt;/code> requests from unknown or unauthorised IP addresses, especially encoded variants such as &lt;code>/%6a_security_check&lt;/code>&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>&lt;code>/var/log/nms/vmanage-server.log&lt;/code>&lt;/td>
&lt;td>Activity involving usernames that begin with &lt;code>viptela-reserved-&lt;/code>&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;p>Two warnings from experience with path-encoding bugs:&lt;/p>
&lt;ol>
&lt;li>&lt;strong>Do not search only for &lt;code>%6a&lt;/code>.&lt;/strong> Any other letter of the path can be encoded (&lt;code>/j_%73ecurity_check&lt;/code>, &lt;code>%4a&lt;/code>, double encoding, etc.). Search for the &lt;em>decoded&lt;/em> path and compare it to the raw one.&lt;/li>
&lt;li>&lt;strong>Plain &lt;code>j_security_check&lt;/code> requests are normal.&lt;/strong> Cisco itself notes that these entries can appear during normal operations. Compare sources and timing against your baseline of administrator IPs.&lt;/li>
&lt;/ol>
&lt;h3 id="quick-check-on-exported-logs">Quick check on exported logs
&lt;/h3>&lt;p>Start by copying the logs off the box (see Section 4), then run a first pass:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e"># Login requests containing percent-encoding (rotated and compressed logs included)&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>zgrep -i &lt;span style="color:#e6db74">&amp;#39;security_check&amp;#39;&lt;/span> serviceproxy-access.log* | grep -E &lt;span style="color:#e6db74">&amp;#39;%[0-9A-Fa-f]{2}&amp;#39;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e"># Activity involving reserved internal accounts&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>zgrep &lt;span style="color:#e6db74">&amp;#39;viptela-reserved-&amp;#39;&lt;/span> vmanage-server.log*
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>The first command misses cases where the encoding is inside &lt;code>security_check&lt;/code> itself. This short script decodes every request path and flags those that only become a login path &lt;em>after&lt;/em> decoding:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-python" data-lang="python">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#f92672">import&lt;/span> gzip&lt;span style="color:#f92672">,&lt;/span> re&lt;span style="color:#f92672">,&lt;/span> sys
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#f92672">from&lt;/span> urllib.parse &lt;span style="color:#f92672">import&lt;/span> unquote
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#75715e"># Adapt this pattern to your access-log format&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>REQ &lt;span style="color:#f92672">=&lt;/span> re&lt;span style="color:#f92672">.&lt;/span>compile(&lt;span style="color:#e6db74">r&lt;/span>&lt;span style="color:#e6db74">&amp;#39;&amp;#34;(GET|POST|PUT|PATCH|DELETE|HEAD|OPTIONS) (\S+)&amp;#39;&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#66d9ef">for&lt;/span> path &lt;span style="color:#f92672">in&lt;/span> sys&lt;span style="color:#f92672">.&lt;/span>argv[&lt;span style="color:#ae81ff">1&lt;/span>:]:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> opener &lt;span style="color:#f92672">=&lt;/span> gzip&lt;span style="color:#f92672">.&lt;/span>open &lt;span style="color:#66d9ef">if&lt;/span> path&lt;span style="color:#f92672">.&lt;/span>endswith(&lt;span style="color:#e6db74">&amp;#34;.gz&amp;#34;&lt;/span>) &lt;span style="color:#66d9ef">else&lt;/span> open
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">with&lt;/span> opener(path, &lt;span style="color:#e6db74">&amp;#34;rt&amp;#34;&lt;/span>, errors&lt;span style="color:#f92672">=&lt;/span>&lt;span style="color:#e6db74">&amp;#34;ignore&amp;#34;&lt;/span>) &lt;span style="color:#66d9ef">as&lt;/span> log:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">for&lt;/span> line &lt;span style="color:#f92672">in&lt;/span> log:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> m &lt;span style="color:#f92672">=&lt;/span> REQ&lt;span style="color:#f92672">.&lt;/span>search(line)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> &lt;span style="color:#f92672">not&lt;/span> m:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">continue&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> raw &lt;span style="color:#f92672">=&lt;/span> m&lt;span style="color:#f92672">.&lt;/span>group(&lt;span style="color:#ae81ff">2&lt;/span>)
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> decoded &lt;span style="color:#f92672">=&lt;/span> unquote(unquote(raw))&lt;span style="color:#f92672">.&lt;/span>lower() &lt;span style="color:#75715e"># also catches double encoding&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#66d9ef">if&lt;/span> &lt;span style="color:#e6db74">&amp;#34;security_check&amp;#34;&lt;/span> &lt;span style="color:#f92672">in&lt;/span> decoded &lt;span style="color:#f92672">and&lt;/span> raw&lt;span style="color:#f92672">.&lt;/span>lower() &lt;span style="color:#f92672">!=&lt;/span> decoded:
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> print(&lt;span style="color:#e6db74">f&lt;/span>&lt;span style="color:#e6db74">&amp;#34;&lt;/span>&lt;span style="color:#e6db74">{&lt;/span>path&lt;span style="color:#e6db74">}&lt;/span>&lt;span style="color:#e6db74">: &lt;/span>&lt;span style="color:#e6db74">{&lt;/span>line&lt;span style="color:#f92672">.&lt;/span>rstrip()&lt;span style="color:#e6db74">}&lt;/span>&lt;span style="color:#e6db74">&amp;#34;&lt;/span>)
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;h3 id="siem-detection-splunk-example">SIEM detection (Splunk example)
&lt;/h3>&lt;p>If the Manager logs are forwarded to your SIEM, the same logic becomes a detection rule. Field names depend on your onboarding:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-spl" data-lang="spl">index=&amp;lt;sdwan_index&amp;gt; source=&amp;#34;*serviceproxy-access.log*&amp;#34;
| rex field=_raw &amp;#34;\&amp;#34;(?&amp;lt;method&amp;gt;[A-Z]+) (?&amp;lt;uri_path&amp;gt;\S+)&amp;#34;
| eval decoded=lower(urldecode(urldecode(uri_path)))
| where like(decoded, &amp;#34;%security_check%&amp;#34;) AND lower(uri_path)!=decoded
| stats count min(_time) as first_seen max(_time) as last_seen values(method) as methods values(uri_path) as raw_paths by host
| convert ctime(first_seen) ctime(last_seen)
&lt;/code>&lt;/pre>&lt;p>Because legitimate clients do not encode letters in this path, &lt;strong>any match deserves triage&lt;/strong>. On the network side, SOCRadar reports Cisco Snort rule &lt;strong>SID 67179&lt;/strong> for this vulnerability. A reverse proxy or WAF in front of the Manager can also block percent-encoded unreserved characters in request paths.&lt;/p>
&lt;h3 id="after-a-hit-what-did-the-attacker-do">After a hit: what did the attacker do?
&lt;/h3>&lt;p>Admin access to the API means the attacker could create access that &lt;strong>survives the patch&lt;/strong>. Use the earlier SD-WAN tradecraft as hunting hypotheses:&lt;/p>
&lt;ul>
&lt;li>New or modified local users, especially with the &lt;strong>netadmin&lt;/strong> role&lt;/li>
&lt;li>API sessions or administrative actions from IP addresses outside your management network&lt;/li>
&lt;li>Template or policy changes, and pushes to edge devices, that do not match a change ticket&lt;/li>
&lt;li>New SSH authorised keys, and NETCONF sessions (TCP 830) from unexpected sources&lt;/li>
&lt;li>Software version changes, including a downgrade followed by a return to the original version&lt;/li>
&lt;li>Gaps, truncation or deletion in the log files themselves&lt;/li>
&lt;/ul>
&lt;h2 id="section-4-response--mitigation">Section 4: Response &amp;amp; Mitigation
&lt;/h2>&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2026_76504/cve_2026_76504_2.png"
loading="lazy"
alt="Five-step response workflow: preserve, hunt, restrict, upgrade, verify"
>&lt;/p>
&lt;p>&lt;em>Figure 2. Suggested order of operations, based on Cisco&amp;rsquo;s advisory guidance. Collect evidence before the upgrade changes the system.&lt;/em>&lt;/p>
&lt;p>&lt;strong>1 — Preserve the evidence first&lt;/strong>&lt;/p>
&lt;p>Before any change, run &lt;code>request admin-tech&lt;/code> on every Manager and copy the existing logs to external storage. An upgrade, a reboot or log rotation can destroy what you need to answer &amp;ldquo;were we compromised?&amp;rdquo;. Cisco also asks for the admin-tech file when you open a TAC case.&lt;/p>
&lt;p>&lt;strong>2 — Hunt from the earliest available date&lt;/strong>&lt;/p>
&lt;p>Exploitation started before the advisory. Run the searches above over the full retention period, not only from 30 September. If retention does not cover September, record that gap explicitly in the incident file.&lt;/p>
&lt;p>&lt;strong>3 — Restrict access immediately&lt;/strong>&lt;/p>
&lt;p>There is &lt;strong>no workaround&lt;/strong>, but exposure can be reduced in minutes. Management interfaces (TCP 443, 22 and 830) should never be reachable from the internet. Allow only known, trusted hosts and place the SD-WAN control components behind a filtering firewall.&lt;/p>
&lt;p>&lt;strong>4 — Upgrade as an emergency change&lt;/strong>&lt;/p>
&lt;p>Move to the first fixed release of your train (see the table in Section 1). Releases earlier than 20.9 must be migrated. This should not wait for the regular patch cycle.&lt;/p>
&lt;p>&lt;strong>5 — Verify and close&lt;/strong>&lt;/p>
&lt;p>Review accounts, keys, templates and policies against a known baseline. Rotate the credentials of Manager administrative accounts. If you suspect compromise, open a TAC case with the CVE number in the title and involve your incident response team.&lt;/p>
&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Action&lt;/th>
&lt;th>Owner&lt;/th>
&lt;th>Done when&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Collect admin-tech and logs&lt;/td>
&lt;td>Network team / SOC&lt;/td>
&lt;td>Archive stored off-box, hash recorded&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Hunt for encoded login paths and reserved users&lt;/td>
&lt;td>SOC&lt;/td>
&lt;td>Results reviewed over the full retention period&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Restrict management access&lt;/td>
&lt;td>Network / Firewall team&lt;/td>
&lt;td>Access tested and refused from an untrusted network&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Upgrade to a fixed release&lt;/td>
&lt;td>Network team&lt;/td>
&lt;td>Version in the Manager matches the fixed release&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Review accounts, keys, templates and policies&lt;/td>
&lt;td>SOC + Network team&lt;/td>
&lt;td>Every difference vs. baseline explained or remediated&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;h2 id="conclusion">Conclusion
&lt;/h2>&lt;p>CVE-2026-76504 shows how small an authentication bypass can be: one percent-encoded letter in a login path. The impact is the opposite. An unauthenticated attacker gets admin control over the system that configures an organisation&amp;rsquo;s whole WAN.&lt;/p>
&lt;p>For SOC teams, the key takeaways are:&lt;/p>
&lt;ol>
&lt;li>&lt;strong>Treat every internet-reachable SD-WAN Manager as potentially compromised&lt;/strong> until it has been hunted, not only patched.&lt;/li>
&lt;li>&lt;strong>Preserve before you patch.&lt;/strong> Run &lt;code>request admin-tech&lt;/code> and export the logs before the upgrade.&lt;/li>
&lt;li>&lt;strong>Hunt for the decoded path, not just &lt;code>%6a&lt;/code>.&lt;/strong> Attackers can encode any character.&lt;/li>
&lt;li>&lt;strong>Patching closes the door, not the access already gained.&lt;/strong> Check accounts, keys and configuration changes.&lt;/li>
&lt;li>&lt;strong>Take the management plane off the internet.&lt;/strong> With several exploited SD-WAN Manager flaws in 2026, exposure is the common factor.&lt;/li>
&lt;/ol>
&lt;p>As the situation evolves, check the Cisco advisory and the CISA KEV catalog for updated versions and indicators.&lt;/p>
&lt;h2 id="sources">Sources
&lt;/h2>&lt;ol>
&lt;li>&lt;a class="link" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU" target="_blank" rel="noopener"
>Cisco — Security Advisory cisco-sa-sdwan-webauth-xr8beuuU (CVE-2026-76504)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener"
>CISA — Known Exploited Vulnerabilities Catalog&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504/" target="_blank" rel="noopener"
>Rapid7 — Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://horizon3.ai/attack-research/vulnerabilities/cve-2026-76504/" target="_blank" rel="noopener"
>Horizon3.ai — CVE-2026-76504: Cisco SD-WAN Auth Bypass&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://watchtowr.com/intelligence/cisco-catalyst-sd-wan-manager-cve-2026-76504-faq/" target="_blank" rel="noopener"
>watchTowr — Cisco Catalyst SD-WAN Manager Vulnerability FAQ: CVE-2026-76504&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://socradar.io/blog/cve-2026-76504-cisco-sd-wan-flaw/" target="_blank" rel="noopener"
>SOCRadar — CVE-2026-76504: Cisco SD-WAN Flaw Exploited&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.helpnetsecurity.com/2026/10/01/new-cisco-sd-wan-zero-day-exploited-in-the-wild-cve-2026-76504/" target="_blank" rel="noopener"
>Help Net Security — New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html" target="_blank" rel="noopener"
>The Hacker News — Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/" target="_blank" rel="noopener"
>BleepingComputer — Cisco warns of new SD-WAN zero-day exploited in attacks&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://fieldeffect.com/blog/exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener"
>Field Effect — Active exploitation of Cisco Catalyst SD-WAN Manager authentication bypass&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.tenable.com/blog/faq-about-the-continued-exploitation-of-cisco-catalyst-sd-wan-vulnerabilities-uat-8616" target="_blank" rel="noopener"
>Tenable — FAQ about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://cwe.mitre.org/data/definitions/177.html" target="_blank" rel="noopener"
>MITRE — CWE-177: Improper Handling of URL Encoding (Hex Encoding)&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.rfc-editor.org/rfc/rfc3986#section-2.3" target="_blank" rel="noopener"
>IETF — RFC 3986, Section 2.3: Unreserved Characters&lt;/a>&lt;/li>
&lt;/ol></description></item></channel></rss>