PRINCIPAL DATA SECURITY CONSULTANT

Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now

3 min read
Cisco has rolled out software hardening updates for its Catalyst SD-WAN Software after an internal security review uncovered multiple critical vulnerabilities affecting the platform. The flaws were identified proactively by Cisco’s own engineering team rather than through external reports, and the company has confirmed there is no evidence of active exploitation in the wild. Even…

Cisco has rolled out software hardening updates for its Catalyst SD-WAN Software after an internal security review uncovered multiple critical vulnerabilities affecting the platform.

The flaws were identified proactively by Cisco’s own engineering team rather than through external reports, and the company has confirmed there is no evidence of active exploitation in the wild.

Even so, given the severity of some of these issues, administrators running Catalyst SD-WAN in any deployment mode should prioritize patching immediately.

Rather than issuing separate advisories for each bug, Cisco grouped the vulnerabilities by their underlying Common Weakness Enumeration (CWE) category and assigned one CVE identifier per group, a move designed to simplify the disclosure and patching process for customers. The most severe issues carry a CVSS score of 9.9, just shy of the maximum possible rating.

CVE-2026-20303 stems from improper input validation and encompasses related weaknesses such as path traversal and external control of file paths.

CVE-2026-20304 covers improper access control, bundling authorization, authentication, and privilege-related bypass issues into a single entry. CVE-2026-20310 involves improper link resolution before file access, a class of bug that can let attackers manipulate symbolic links to reach unintended files.

Together, these three flaws represent the most dangerous risks in this advisory. Rounding out the list, CVE-2026-20312 scores 8.8 and relates to cleartext storage of sensitive information, meaning credentials or other secrets could be exposed if the underlying system is compromised. CVE-2026-20313 scores 7.7 and involves improper validation of a specified quantity in input, a less severe but still notable weakness.

CVE ID Highest CVSS Score Vulnerability Class (CWE) Description
CVE-2026-20303 9.9 CWE-20 Improper input validation (covers input validation, path traversal, and external path control)
CVE-2026-20304 9.9 CWE-284 Improper access control (covers authorization, authentication, privileges, and bypasses)
CVE-2026-20310 9.9 CWE-59 Improper link resolution before file access
CVE-2026-20312 8.8 CWE-312 Cleartext storage of sensitive information
CVE-2026-20313 7.7 CWE-1284 Improper validation of specified quantity in input

The vulnerabilities affect Cisco Catalyst SD-WAN Software across every deployment model, regardless of how the device is configured. That includes on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud environments, and Cisco SD-WAN for Government under FedRAMP.

No configuration setting or feature toggle exempts a device from exposure, which makes this a broad-reaching advisory for enterprises and government agencies relying on Cisco’s SD-WAN fabric.

Cisco has been explicit that there are no workarounds for any of these vulnerabilities, leaving software upgrades as the only viable remediation path. Organizations running Catalyst SD-WAN releases earlier than 20.9 must migrate to a supported version entirely, since those older branches will not receive a patch.

Fixed builds include 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2, depending on which branch is currently in use. Several affected releases, including 20.11, 20.13, 20.14, and 20.16, have already reached End of Software Maintenance, so Cisco is urging customers on those versions to move to a currently supported release rather than simply applying a point fix.

Cisco Catalyst SD-WAN Release First Fixed Release
Earlier than 20.9 Migrate to a fixed release
20.9 20.9.10
20.10 20.12.8.1
20.11¹ 20.12.8.1
20.12 20.12.8.1
20.13¹ 20.15.6
20.14¹ 20.15.6
20.15 20.15.6
20.16¹ 20.18.4
20.18 20.18.4
26.1 26.1.2

Customers using Cisco SD-WAN Cloud under a Cisco-managed service do not need to take any action, as the vendor has already applied the fix in Release 20.15.602 on the backend. Administrators can confirm their current remediation status through the Help function within the service GUI.

Notably, Cisco disclosed that these flaws were uncovered using a combination of traditional internal testing processes and frontier AI models, signaling a shift toward AI-assisted vulnerability discovery in enterprise security research.

While no public exploitation has been reported, the high CVSS scores mean these bugs could become attractive targets once technical details circulate. Organizations should verify their current Catalyst SD-WAN version against Cisco’s advisory and schedule upgrades promptly, since delaying patching on internet-facing SD-WAN infrastructure carries outsized risk.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now appeared first on Cyber Security News.


Kaynak: Cyber Security News

Yayin Tarihi: 06.08.2026 03:46

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir