Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
August 6, 2026 · The Hacker News · Severity: CRITICAL
Cisco has released patches to address 12 critical vulnerabilities affecting its Catalyst SD-WAN and IOS XE Software, including three flaws with a CVSS score of 9.9. These vulnerabilities, discovered during internal security testing using AI models, impact Cisco Catalyst SD-WAN Software across all configurations and IOS XE Software in autonomous or controller modes. Key issues include improper input validation, access control, and link resolution vulnerabilities, such as CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310. Cisco has urged customers to update to fixed versions, including 20.9.10, 20.12.8.1, and 26.1.2 for SD-WAN, and 17.9.10, 17.12.8, and 26.1.2 for IOS XE. While no active exploitation has been reported, the severity of these flaws underscores the importance of prompt patching. Additionally, Cisco addressed a high-severity flaw in its Integrated Management Controller (IMC) web interface, CVE-2026-20200, which allows authenticated attackers to execute arbitrary commands and escalate privileges to root. A proof-of-concept exploit for this vulnerability is already available. Security researcher Christoph Peil highlighted the risks, noting that compromising the IMC could undermine the trust anchor of server hardware, bypassing traditional security measures. This disclosure follows Cisco’s recent warning about active exploitation of CVE-2026-20316 in its Secure Firewall Management Center Software, which enables low-privilege accounts to access sensitive data. These vulnerabilities highlight the critical need for organizations to prioritize updates to mitigate potential risks to their network infrastructure.
Key Takeaways
- Cisco patched 15 vulnerabilities across SD-WAN and IOS XE platforms, including three with CVSS scores of 9.8 or higher involving remote code execution.
- One of the critical flaws (CVE-2026-20200) enables unauthenticated remote attackers to execute arbitrary commands on affected Cisco IMC devices.
- Cisco has released security advisories for all patched CVEs — administrators should update firmware immediately.