Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Pasillo entre racks de equipos de red en una sala técnica
9 min read

CVE-2026-76504: the rule compared strings, not resources

Cisco published the Catalyst SD-WAN Manager advisory yesterday: CVSS 9.8, exploited before the advisory was published, and CISA allowing three days to fix it. Authentication did not fail. What failed was the list deciding which requests have to go through it: the list said /j_security_check and the request said /%6a_security_check, the same path with the j written in hex. Two different strings to the list, the same resource to the server behind it, and an administrator fits in that one-character gap. What decides how you read the rest is why that path HAD to be exempt from the session check: it is where the session is obtained, and if you protected it nobody could ever log in. So the flaw is not having the exception, it is how you check whether a request falls inside it. And that is not Cisco's: it happens anywhere the layer protecting a path by name is not the one resolving it. Inside: the table of branches and first fixed releases, the thirty-second test for your own proxy, the two greps that answer whether anyone got in before the patch, and the awkward question of whether those logs ever leave the box.

Armario de red mural abierto en una oficina, con panel de parcheo, dos conmutadores de rack y un mazo de latiguillos peinado sobre el raíl lateral
9 min read

A CVE is no longer one bug: Cisco has changed the unit of measurement

On 19 August Cisco published two advisories carrying five CVEs scored 10.0 between them. They are not five bugs: each identifier groups an entire class of bugs and carries the score of the worst one in the bag. Across the four hardening advisories we reviewed the mitigation line says the same thing, "none." This is not a complaint about Cisco: it is that the unit you count vulnerabilities in has changed size, and your inventory has not noticed.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN