This document describes steps to identify and fix a critical SD-WAN security vulnerability per the PSIRT advisory dates September 30,2026. Cisco strongly recommends upgrading to a fixed software release to remediate this issue.
Cisco recommends that you have knowledge of these topics:
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
For detailed background information and the latest updates, refer to the official PSIRT advisory page.
This advisory is available at this link:
This defect is addressed by this PSIRT advisory:
This advisory affects Cisco Catalyst SD-WAN Manager (vManage).
Note: All SD-WAN Managers (vManage) that run a release earlier than the first fixed release are vulnerable and require an immediate upgrade. However, not all Catalyst Managers show evidence of compromise.
Required Action: Collect admin-techs from all Catalyst SD-WAN Managers, upgrade all to a fixed release, and open a Cisco TAC case so TAC can scan your admin-techs for indicators of compromise.
TAC is available to:
Note: Do not wait for TAC scan results before upgrading. Upgrading to a fixed release is the highest priority and closes the vulnerability. The TAC scan in Step 3 determines whether any further action is needed after the upgrade.
Required: Collect admin-tech files from all Managers (vManage) before upgrading to ensure no diagnostic data is lost. These files are used by TAC in Step 3 to scan your environment for indicators of compromise.
Collection:
Note: For admin-tech generation, select Log and Tech options. Core is not required.
Collect an Admin-Tech in SD-WAN Environment and Upload to TAC Case
Note: TAC analyzes these files to assess your environment for indicators of compromise and guide the appropriate remediation path.
For those who cannot share admin-tech files, manual verification steps are available. These steps provide preliminary indicators that must be documented and shared with TAC.
See the Manual Verification Steps section at the end of this document for detailed procedures. Document all findings and provide them to TAC in your support case.
After collecting admin-techs in Step 1, upgrade all Managers (vManage) to a fixed software version.
Important: Do not wait for TAC scan results before upgrading. Upgrading to a fixed release is the highest priority and closes the vulnerability. The TAC scan in Step 3 determines whether any further action is needed after the upgrade.
Select the appropriate version from the Fixed Software Versions table in this document.
Warning: Upgrade must remain within your current major release. Do not upgrade to a higher major release without explicit TAC guidance.
Upgrade SD-WAN Controllers with the Use of vManage GUI or CLI
Note: If you encounter any issues during the upgrade, open a TAC case for upgrade support.
After upgrading in Step 2, open a Cisco TAC support case and upload the admin-tech files collected in Step 1. TAC scans the admin-techs for indicators of compromise.
Required Actions:
Note: TAC analyzes the admin-tech files and communicates the results of the scan. If no indicators of compromise are found, no further action beyond the upgrade is required.
If TAC identifies indicators of compromise in your environment, TAC contacts you with specific remediation guidance. Complete all instructions provided by TAC.
If no indicators of compromise are identified, the upgrade completed in Step 2 is sufficient and no further remediation is required.
These software releases contain the fix for this vulnerability. Upgrade to the first fixed release in your current release train.
| Cisco Catalyst SD-WAN Software Release | First Fixed Release | Available Software |
|---|---|---|
| Earlier than 20.91 | Migrate to a fixed release. | |
| 20.9 | 20.9.10.1 | 20.9.10.1 upgrade images for vManage |
| 20.12 | 20.12.8.2 | 20.12.8.2 upgrade images for vManage |
| 20.15 | 20.15.6.1 | 20.15.6.1 upgrade images for vManage |
| 20.18 | 20.18.4.1 | 20.18.4.1 upgrade images for vManage |
| 26.1 | 26.1.2.1 | 26.1.2.1 upgrade images for vManage |
| 26.2 | 26.2.1 | 26.2.1 upgrade images for vManage |
1 These releases have reached End of Software Maintenance. Cisco strongly encourages customers to upgrade to a supported release.
The Cisco Product Security Incident Response Team (PSIRT) validates only the affected and fixed release information that is documented in the advisory.
Note: Cisco has also addressed this vulnerability in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.605, which is cloud based. No user action is required. Customers can determine the current remediation status or software version by using the Help function in the service GUI.
Important References:
Note: Admin-tech collection is the preferred and recommended method. Only use manual verification if you absolutely cannot collect and share admin-tech files. If you cannot collect admin-tech files, use these manual steps to gather preliminary indicators for TAC.
Note:
Requirements: These steps must be performed on all Managers (vManage), including every cluster member and every Manager in a Disaster Recovery (DR) site. Access the log files from vshell (vshell from the Manager CLI), and review both the current and the rotated log files.
This advisory has two indicators of compromise. Both relate to entries for j_security_check in which a character of the request is encoded (for example /%6a_security_check), from unknown or unauthorized IP addresses.
Important: The examples in this section show the use of %6a as the encoded character j in the request. This is only an example, and the vulnerability allows any one character that is encoded in the request to be used.
Note: Cisco Catalyst SD-WAN Manager systems that are exposed to the internet and that have ports exposed to the internet are at risk of exposure to compromise. In some instances, these indicators of compromise can occur during standard operations. Therefore, they must be assessed against normal network posture to identify and avoid false positives.
| Indicator | Log File | What It Means | Verification |
|---|---|---|---|
Encoded j_security_check request received |
/var/log/nms/containers/service_proxy/serviceproxy-access.log* |
A client sent a request of this type to the Manager. | Verification 1 |
Encoded j_security_check request processed for a viptela-reserved-* user |
/var/log/nms/vmanage-server.log* |
The Manager processed a request of this type for a viptela-reserved-* user (a reserved system service account). |
Verification 2 |
Audit the serviceproxy-access.log file, located at /var/log/nms/containers/service_proxy/serviceproxy-access.log, for entries that are related to j_security_check from unknown or unauthorized IP addresses, as shown in this example:
[2026-09-29T23:11:13.948-05:00] "POST /%6a_security_check HTTP/1.1" 200 - 48 0 4 - "10.10.10.47,192.168.1.174" "Mozilla/5.0" "92980fc6-bb3c-4b67-8a6d-af5ceb236d4c" "vmanage-9999.example.com" "127.0.0.1:8080"
Certain log files in the vManage system are restricted behind root access and cannot be accessed directly by customers. To review these logs, customers must generate an admin-tech file.
Interpret Results and Document for TAC
If no such entries are found:
If such entries are found:
Audit the vmanage-server.log file, located at /var/log/nms/vmanage-server.log, for entries that are related to j_security_check from unknown or unauthorized IP addresses, specifically being called for users that include names starting with viptela-reserved-, as shown in this example:
29-Sep-2026 23:11:13,952 CDT [] [vManage-new] [UserUtils] (default task-127462) |default| Request Stored in Map is (/%6a_security_check) for user (viptela-reserved-..)
Note: The viptela-reserved system service accounts are documented in the Authentication, Authorization, and Accounting section of the Cisco Catalyst SD-WAN Systems and Interfaces Configuration Guide.
Interpret Results and Document for TAC
If no such entries are found:
If such entries are found:
Q: What is the first step to address this security advisory?
A: Collect admin-tech files from all Managers (vManage), then upgrade all Managers to a fixed software version. After upgrading, open a TAC case and upload the admin-techs so TAC can scan your environment for indicators of compromise.
Q: Which components are affected by this advisory?
A: Only Cisco Catalyst SD-WAN Manager (vManage) is affected.
Q: Do we need to upgrade the Controllers, Validators, or edge routers as well?
A: No, not to address this advisory. Upgrade all Managers (vManage) to a fixed release, and use the Controller Compatibility Matrix to confirm that the new Manager release is compatible with your other components.
Q: Is a workaround available?
A: No. There are no workarounds that address this vulnerability. Upgrade to a fixed release.
Q: What version do I need to upgrade to?
A: Upgrade to the first fixed release in your current release train as soon as possible. Refer to the Fixed Software Versions table in this document. TAC confirms the appropriate version for your specific environment.
Q: I already upgraded to a fixed release for a previous SD-WAN security advisory. Do I need to upgrade again?
A: Yes, unless your current release is at or later than the first fixed release in your train in the Fixed Software Versions table. Fixed releases for earlier advisories do not necessarily include the fix for this vulnerability.
Q: Do I need to collect admin-techs from all Managers?
A: Yes. TAC requires admin-tech files from every Manager (vManage), including every cluster member and every Manager in a Disaster Recovery (DR) site, to properly assess your environment.
Q: Can I check for indicators of compromise myself?
A: Yes. If you cannot collect admin-tech files, use the Manual Verification Steps on every Manager and share the results with TAC. Admin-tech collection remains the preferred method, and TAC makes the official assessment determination.
Q: How does TAC determine if my system has been compromised?
A: TAC analyzes the admin-tech files using specialized tools to assess your environment for indicators of compromise.
Q: What happens if indicators of compromise are identified?
A: TAC contacts you to discuss next steps and guidance specific to your environment. Cisco does not perform the remediation on your behalf — TAC provides the guidance needed for you to proceed.
Q: Can I start the upgrade before TAC analyzes my admin-techs?
A: Yes. Collect admin-techs, upgrade to a fixed release, and then open a TAC case so TAC can scan the admin-techs for indicators of compromise.
Q: Is downtime expected during remediation?
A: The impact depends on your deployment architecture and the remediation path. TAC provides guidance on minimizing service impact during the process.
Q: I have a cloud-hosted SD-WAN overlay. What are my options for upgrading?
A: For cloud-hosted overlays, customers have two options:
Q: We are a Cisco-hosted overlay. Do we need to review any access rules on SSP?
A: All Cisco-hosted customers are advised to review their own Allowed Inbound Rules in SSP > Overlay Details > Allow Inbound rules and ensure only the necessary prefixes from your side are allowed. These rules are for management access only and do not apply to edge routers.
Q: Does Cisco TAC provide forensic analysis or investigation services for this vulnerability?
A: Cisco TAC can assist customers by scanning for Indicators of Compromise (IoCs) related to this vulnerability. However, TAC does not perform in-depth forensic analysis or incident investigations. For comprehensive forensic work or detailed security investigations, we recommend that customers engage their preferred third-party Incident Response (IR) firm.
Q: What are the general best practices or ways to reduce vulnerabilities for my SD-WAN overlay?
A: Refer to the Cisco Catalyst SD-WAN Hardening Guide for best practices and recommendations to reduce vulnerabilities in your SD-WAN overlay.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
30-Sep-2026
|
Initial Release |