CVE-2026-76504: the rule compared strings, not resources
Cisco published the Catalyst SD-WAN Manager advisory yesterday: CVSS 9.8, exploited before the advisory was published, and CISA allowing three days to fix it. Authentication did not fail. What failed was the list deciding which requests have to go through it: the list said /j_security_check and the request said /%6a_security_check, the same path with the j written in hex. Two different strings to the list, the same resource to the server behind it, and an administrator fits in that one-character gap. What decides how you read the rest is why that path HAD to be exempt from the session check: it is where the session is obtained, and if you protected it nobody could ever log in. So the flaw is not having the exception, it is how you check whether a request falls inside it. And that is not Cisco's: it happens anywhere the layer protecting a path by name is not the one resolving it. Inside: the table of branches and first fixed releases, the thirty-second test for your own proxy, the two greps that answer whether anyone got in before the patch, and the awkward question of whether those logs ever leave the box.