Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco patches 12 critical SD-WAN and IOS XE flaws, including three 9.9 CVSS score bugs.
Summary
Cisco has released updates to fix twelve security vulnerabilities affecting its Catalyst SD-WAN and IOS XE Software. Three of these flaws, all with a CVSS score of 9.9, involve improper input validation, access control, and link resolution. The company stated these issues were discovered during internal testing and are not known to be actively exploited.
Full text
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs Ravie LakshmananAug 06, 2026Network Security / Vulnerability Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models [...] and are not known to be actively exploited," Cisco said, urging customers to apply the necessary updates for optimal protection. The vulnerabilities impacting Catalyst SD-WAN Software are listed below - CVE-2026-20303 (CVSS score: 9.9) - An improper input validation vulnerability (which also covers path traversals) CVE-2026-20304 (CVSS score: 9.9) - An improper access control vulnerability CVE-2026-20310 (CVSS score: 9.9) - An improper link resolution before file access vulnerability CVE-2026-20312 (CVSS score: 8.8) - A cleartext storage of sensitive information vulnerability CVE-2026-20313 (CVSS score: 7.7) - An improper validation of specified quantity in input The issues have been addressed in the following versions of Cisco Catalyst SD-WAN Software - 20.9 (Fixed in 20.9.10) 20.10 (Fixed in 20.12.8.1) 20.111 (Fixed in 20.12.8.1) 20.12 (Fixed in 20.12.8.1) 20.131 (Fixed in 20.15.6) 20.141 (Fixed in 20.15.6) 20.15 (Fixed in 20.15.6) 20.161 (Fixed in 20.18.4) 20.18 (Fixed in 20.18.4) 26.1 (Fixed in 26.1.2) Earlier than 20.9 (Migrate to a fixed release) The vulnerabilities impacting IOS XE Software relate to improper access control, command injection, and improper input validation - CVE-2026-20267 (CVSS score: 9.0) - An improper access control vulnerability CVE-2026-20268 (CVSS score: 8.6) - A set of buffer overflow and out-of-bounds write vulnerabilities CVE-2026-20269 (CVSS score: 8.6) - An improper control of a resource through its lifetime vulnerability CVE-2026-20270 (CVSS score: 8.6) - An incorrect calculation vulnerability (which also covers arithmetic or numeric conversion errors including integer overflow, underflow, and truncation) CVE-2026-20271 (CVSS score: 8.6) - An insufficient control flow management vulnerability (which also covers infinite loops, uncontrolled recursion, and race conditions) CVE-2026-20272 (CVSS score: 9.8) - An improper neutralization of special elements vulnerability (which also covers command, operating system, and argument injection) CVE-2026-20273 (CVSS score: 8.6) - An improper input validation vulnerability (which also covers path traversals) The set of seven flaws has been addressed in the following versions of Cisco IOS XE Software - 17.9 (Fixed in 17.9.10) 17.12 (Fixed in 17.12.8) 17.15 (Fixed in 17.15.6) 17.18 (Fixed in 17.18.4 and 17.18.4a) 26.1 (Fixed in 26.1.2) Separately, Cisco also shipped fixes to address a high-severity security flaw in the web-based management interface of Integrated Management Controller (IMC) (CVE-2026-20200) for which it acknowledged a proof-of-concept (PoC) exploit is available. CVE-2026-20200 (CVSS score: 8.8) - An improper validation of user-supplied input that could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. CVE-2026-20288 (CVSS score: 6.5) - An improper validation of user-supplied input that could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. "One should be clear about what a compromise of the IMC means: the controller sits in a position where it can influence the BIOS and SecureBoot and interact with the operating system above it," security researcher Christoph Peil, who discovered and reported CVE-2026-20200, said. "An attacker who gains root here can thereby nest themselves deeply and persistently in the system – far below what classic protective measures such as EDR solutions at the operating-system level can even see. The trust anchor of the entire server hardware is thus compromised." The disclosure comes less than a week after the network equipment company warned of active exploitation of CVE-2026-20316 (CVSS score: 5.3), a vulnerability in Cisco Secure Firewall Management Center (FMC) Software that could allow a low-privilege account to access sensitive data within susceptible systems. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Access Control, cisco, Command Injection, enterprise security, hardware security, network security, Patch Management, Software Security, Vulnerability ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders
Indicators of Compromise
- cve — CVE-2026-20303
- cve — CVE-2026-20304
- cve — CVE-2026-20310
- cve — CVE-2026-20312
- cve — CVE-2026-20313
- cve — CVE-2026-20267
- cve — CVE-2026-20268
- cve — CVE-2026-20269
- cve — CVE-2026-20270
- cve — CVE-2026-20271
- cve — CVE-2026-20272
- cve — CVE-2026-20273
- cve — CVE-2026-20200
- cve — CVE-2026-20288