Security Advisory Desk
unratedQCS priority 76/100Cisco

CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Cisco Catalyst SD-WAN Manager has a security weakness in how it processes encoded information in web requests. This flaw allows a remote attacker, without needing any login, to gain admin-level access to the system by exploiting improper handling of URL encoding.

QCS published 6/10/2026, 3:04:23 am ISTVendor disclosure 30/9/2026, 5:30:00 am ISTVerified 6/10/2026, 3:04:23 am ISTRevision 1

In plain language

What this advisory means

Cisco Catalyst SD-WAN Manager has a security weakness in how it processes encoded information in web requests. This flaw allows a remote attacker, without needing any login, to gain admin-level access to the system by exploiting improper handling of URL encoding.

Technical explanation

How the issue affects the environment

The vulnerability in Cisco Catalyst SD-WAN Manager involves improper handling of URI encoding due to a hex encoding flaw. Specifically, an unauthenticated attacker can craft HTTP requests with manipulated URI encodings that bypass normal access controls. This leads to unauthorized admin privilege access on the affected system. The underlying issue is categorized as CWE-177, involving improper handling or comparison of encoded data within HTTP requests.

Operational impact

Why teams should care

An attacker gaining admin privileges remotely without authentication risks full control over the Catalyst SD-WAN Manager device. This can lead to system compromise, interception or manipulation of network traffic managed by the device, and disruption of enterprise WAN operations. The exposure imposes significant operational and security risks for organizations running affected versions of the product.

Immediate action

Organizations should apply mitigations as instructed by Cisco and follow the Cybersecurity and Infrastructure Security Agency's (CISA) Binding Operational Directive 26-04, which prioritizes security updates based on risk. If mitigations are unavailable, discontinuing use of the affected product is advised. Stakeholders must assess each asset's internet exposure, comply with BOD 26-04 patching requirements, and perform forensic triage as mandated.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • CISA Known Exploited Vulnerabilities Catalog entry dated 2026-09-30
  • Cisco security advisory URL referenced in CISA catalog
  • CISA Binding Operational Directive 26-04 guidelines
  • Forensic triage requirement per BOD 26-04

Authoritative reference

CISA Known Exploited Vulnerabilities

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source