Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-09-30) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-76504.

What it is

CVE-2026-76504 sits in the API session-based authentication management of Cisco Catalyst SD-WAN Manager. The flaw is in how the system handles URI encoding in HTTP requests: a specific API endpoint is meant to be restricted by an authentication rule, but a crafted request using hex-encoded characters in the URI can bypass that rule.

An attacker needs only network access to the SD-WAN Manager’s API — no credentials, no user interaction. By sending a single crafted HTTP request, they can reach the restricted endpoint and interact with the API as the admin user, which is full administrative control over the platform.

This is a management-plane issue: it affects the interface used to configure and control the SD-WAN fabric, not the data plane carrying user traffic. Given the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), exploitation requires no privileges, no user interaction, and low attack complexity, and results in full compromise of confidentiality, integrity and availability.

The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-09-30, so it is known to be exploited in the wild.

What to do

  • Restrict network access to the SD-WAN Manager API and management interface immediately — it should not be reachable from untrusted networks or the general internet.
  • Check the Cisco advisory for the fixed release, as fixed version numbers are not included in the current record here and should come directly from Cisco.
  • Given the KEV listing, treat this as an active threat: audit SD-WAN Manager logs for unexpected API calls, particularly requests with unusual or hex-encoded URI paths hitting authentication-restricted endpoints.
  • Review admin account activity and API session logs for anything inconsistent with known administrative behaviour, since a successful exploit grants admin-level API access without normal authentication.
  • Once a fix is available from Cisco, apply it as a priority given the CRITICAL severity and confirmed exploitation.

For leadership 🧭

Executive summary. An unauthenticated attacker who can reach the SD-WAN Manager’s API can send a single crafted request and gain full administrative control of the platform that configures your entire SD-WAN fabric. This is already listed as exploited in the wild, so exposed management interfaces need action today, not at the next patch cycle.

Why it matters:

  • The bypass targets the authentication rule guarding a specific API endpoint in SD-WAN Manager, not a peripheral feature, so a successful request hands over admin-level API access directly.
  • No credentials or user interaction are needed — only network reachability to the management API — and CISA’s KEV listing confirms this is being exploited now.
  • Compromise of SD-WAN Manager means compromise of the management plane controlling the whole SD-WAN fabric: configuration, routing policy and device control, not just a single appliance.
  • No fixed version is yet recorded here, so the only mitigation available immediately is cutting off exposure rather than patching.

Now / Next / Later:

  • Now: Immediately restrict network access to the SD-WAN Manager API and management interface so it is reachable only from trusted management networks, not the internet or general internal networks.
  • Next: Check the Cisco advisory directly for the fixed release and schedule an upgrade as a priority once one is confirmed, given the CRITICAL score and active exploitation.
  • Later: Build a standing rule that SD-WAN Manager and similar management-plane interfaces are never exposed to untrusted networks by default, and add log monitoring for hex-encoded or unusual URI paths hitting authentication-restricted API endpoints.

Source