Cisco SD-WAN Manager Vulnerability Exploited in the Wild: Federal Agencies Must Act
A critical vulnerability in Cisco's SD-WAN Manager has been exploited in the wild, allowing unauthenticated attackers to gain administrative access. The flaw, tracked as CVE-2026-76504, stems from improper handling of URL/URI encoding within the j_security_check path. By substituting the character 'j' with its URI-encoded equivalent, %6a, an attacker can bypass authentication rules and access the management API.
The vulnerability has been actively exploited since September 2026, and Cisco PSIRT confirmed this in a recent statement. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026, prompting federal agencies to remediate the issue by October 3, 2026.
The exploitation of this vulnerability highlights a broader structural issue in network infrastructure: the pattern of trust-through-defaults. Manufacturers often design management interfaces with implicit trust assumptions that fail when exposed to sophisticated, automated exploitation techniques.