Photo by Esten Erbol on Unsplash. Source: https://unsplash.com/photos/man-typing-on-keyboard-in-front-of-multiple-computer-monitors-Nm_hDwuVtcw (Unsplash License).

Cisco’s fix is out, and it does not undo what an attacker with admin API access could already have done.

  • CVE-2026-76504 scores 9.8. The API authentication rule matched the literal request path, so percent-encoding a single character (/%6a_security_check) walked past it and returned admin API access to an unauthenticated caller.
  • Cisco confirmed exploitation in September and shipped fixed releases. There is no workaround and no configuration toggle, so the only mitigation left is keeping the manager off the internet.
  • CISA listed it on the Known Exploited Vulnerabilities catalog on September 30 and gave federal agencies until October 3. Its directive also requires checking whether the system was compromised before the patch.
  • Cisco’s SD-WAN line has produced nine entries on the Known Exploited Vulnerabilities catalog this year alone. Fixes in February and May did not cover this one, so patching on schedule left operators exposed again.

Read the full analysis. One Encoded Character Bypassed Cisco SD-WAN Manager Authentication

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.