OFFSEC · Offensive Security

The same authentication boundary has failed four times in one year, and the attacker population has widened

Cisco disclosed a fourth exploited authentication or privilege flaw in the Catalyst SD-WAN control plane on 30 September. The pattern matters more than the CVE: what began as one sophisticated actor working a zero-day has become a broader set of opportunistic operators against the same boundary.

Cisco published a security advisory on 30 September 2026 for CVE-2026-76504, an API authentication bypass in Catalyst SD-WAN Manager scored 9.8, and stated that its product security incident response team had become aware of active exploitation during September [1]. An unauthenticated attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user [2]. There are no workarounds that address this vulnerability [1].

Read alone, that is a patch note. Read against the year, it is the fourth time the same authentication boundary in the same management plane has failed under active exploitation, and the composition of the attacker population has changed around it.

The advisory

The flaw class is worth naming precisely because it recurs: CWE-177, improper handling of URL encoding [1]. The authentication rule is evaluated against a path that the application later resolves differently. Cisco’s own detection guidance follows from that mechanism without disclosing it – audit the service proxy access log for URL-encoded variants of the authentication path, and the Manager server log for accounts whose names begin with a reserved internal prefix [1][3].

Fixed releases exist for every supported branch: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1, and cloud release 20.15.605 [1][2]. Cloud-hosted customers have already received the fix; on-premises deployments carry the work [3]. Rapid7 strongly recommends that organisations upgrade affected systems to a fixed release on an emergency basis, outside of normal patch cycles, and investigate internet-facing systems for signs of exploitation [2].

The US catalogue entry could not be read for this article because cisa.gov was unreachable during research. It is reported here only where a cited publisher states it.

The pattern this sits in

On 25 February Cisco published advisory cisco-sa-sdwan-rpa-EHchtZk for CVE-2026-20127, an authentication bypass in the peering mechanism of Catalyst SD-WAN Controller and Manager, scored 10.0, with the Cisco PSIRT aware of limited exploitation and no workarounds available [4][7]. Talos published the same day, clustering the activity under an actor it designates UAT-8616 and assessing with high confidence that it is a highly sophisticated threat actor [5]. The important detail is the timeline: Talos found exploitation dating back at least three years, to 2023 [5]. The February disclosure did not open the window. It documented one that had been open for years.

The tradecraft Talos described is the kind that survives patching. The actor escalated to root by downgrading the software version, exploiting the older CVE-2022-20775, then restoring the original version [5]. Reported persistence included creating mimic user accounts, adding SSH keys for root, modifying startup scripts, using NETCONF over port 830, and clearing logs [10]. A version downgrade followed by an upgrade and a reboot is a detection opportunity most change-management processes would record and most monitoring would ignore.

In March came CVE-2026-20122, CVE-2026-20128 and CVE-2026-20133, and in May CVE-2026-20182, another authentication bypass at 10.0 affecting Controller and Manager, which SOCRadar describes as permitting administrative privileges by authenticating as a high-privileged internal non-root account [6][7][8]. Talos’s May assessment separates the populations, and this is the finding to carry: exploitation of CVE-2026-20182 appeared limited and was clustered to UAT-8616, while the March flaws saw widespread in-the-wild active exploitation by a series of threat actors distinct from UAT-8616, deploying webshells, the XMRig miner, the Sliver and AdaptixC2 command frameworks, and credential stealers targeting JWT keys and AWS credentials [6].

That is the trajectory to plan against. A control-plane authentication boundary that one capable actor worked quietly for three years becomes, once the flaw class is public, a commodity target for operators whose goal is a miner or a credential set. The sophisticated actor is the reason the boundary is interesting. The opportunists are the reason an unpatched instance will be found.

On how many such advisories 2026 has produced, sources do not agree, and the disagreement is worth publishing rather than resolving. Cisco’s SD-WAN product advisory index lists five 2026 advisories, of which two are authentication bypasses – a Controller bypass dated 16 June and the Manager API bypass dated 30 September [11]. Those dates do not line up cleanly with the February and May CVE dates recorded by Talos, Tenable and SOCRadar [5][6][7][8]. The likeliest explanation is that an index filtered to one product family, and advisories revised after first publication, produce different counts from the same underlying events. The count depends on which index is read; the pattern does not.

What to do

  • Upgrade to a fixed release on an emergency basis. There is no workaround for CVE-2026-76504, and cloud-hosted instances are already fixed while on-premises ones are not [1][2][3].
  • Audit the two logs Cisco names – serviceproxy-access.log for URL-encoded variants of the authentication path, and vmanage-server.log for accounts with the reserved internal prefix – and do it before the upgrade, because an update can remove evidence [1][3].
  • Hunt the persistence, not only the entry. Unexplained local accounts, added root SSH keys, modified startup scripts, NETCONF sessions on port 830, cleared logs, and any version downgrade followed by an upgrade and reboot [5][10].
  • Restrict the administrative interface to trusted management networks and approved administrative hosts, and correlate administrative activity from unfamiliar addresses against firewall, proxy, authentication and network telemetry [3].
  • Deploy the published network detections where you run the sensors for them. Talos lists Snort coverage for the earlier SD-WAN CVEs and ClamAV signatures, with indicators in its public repository [6].
  • Treat JWT signing keys and cloud credentials reachable from the management plane as exposed if an instance was internet-facing and unpatched during a known exploitation window, because stealing exactly those was observed [6].

The R3KONX view

A network management plane is a single point of authority over routing for an entire estate, which makes its authentication boundary the highest-value boundary most organisations operate and the one they are least able to take offline. Four exploited failures of that boundary in ten months is not a patching story. It is a design-assurance question for the vendor and an architecture question for the operator: what else must be true for a compromised Manager not to become a compromised network?

For regional operators the practical point is that the warnings have been arriving through APAC channels too. Singapore’s Cyber Security Agency published its alert on the February flaw on 26 February, reporting it as exploited in the wild and advising immediate upgrade and a review for indicators of compromise [9]. Organisations that acted then have a reference point for how long their own cycle takes. Those that did not should assume the current flaw will follow the same path the March ones did: from one actor who hid well to many who do not bother.

Sources

Every R3KONX article cites its primary material. 11 sources, in order of first citation. Links open the original publication.

  1. Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability (cisco-sa-sdwan-webauth-xr8beuuU), CVE-2026-76504 Cisco Security Advisory · 2026-09-30
  2. Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504) Rapid7 · 2026-09-30
  3. Active exploitation of Cisco Catalyst SD-WAN Manager authentication bypass Field Effect · 2026-09-30
  4. Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (cisco-sa-sdwan-rpa-EHchtZk), CVE-2026-20127 Cisco Security Advisory · 2026-02-25
  5. Active exploitation of Cisco Catalyst SD-WAN by UAT-8616 Cisco Talos Intelligence Group · 2026-02-25
  6. Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos Intelligence Group · 2026-05-14
  7. CVE-2026-20127: Cisco Catalyst SD-WAN Controller and Manager Zero-Day Authentication Bypass Tenable · 2026-02-25
  8. CVE-2026-20182: Cisco Catalyst SD-WAN Auth Bypass Added to CISA KEV SOCRadar · 2026-05
  9. Active Exploitation of Critical Vulnerability in Cisco Catalyst SD-WAN (AL-2026-019) Cyber Security Agency of Singapore · 2026-02-26
  10. UAT-8616 Exploits Cisco SD-WAN Zero-Day for Persistent Access Avertium · 2026-03-02
  11. Cisco SD-WAN - Security Advisories, Responses and Notices Cisco · 2026-10-01

This article was researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveats: cisa.gov could not be retrieved during research, so Known Exploited Vulnerabilities catalogue entries and deadlines are reported as the cited publishers state them rather than read directly; the count of 2026 SD-WAN advisories differs depending on which Cisco index is consulted and the discrepancy is described rather than resolved; and NVD returned no entry content for the newest CVE, so no independent severity assessment is cited. Corrections: event@r3konx.asia

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.