Cisco Patches 12 Catalyst SD-WAN and IOS XE Flaws, Three Rated CVSS 9.9
Cisco's newest hardening release patches 12 Catalyst SD-WAN and IOS XE flaws — three of them rated CVSS 9.9 and a fourth at 9.8. Cisco says none are exploited yet, which makes this a patch-priority call: take the criticals first, schedule the rest by exposure.
Cisco's newest hardening release reads as a patch-priority problem rather than a breach — but three of the twelve fixes sit at the very top of the severity scale.
Cisco has shipped fixes for 12 flaws across its Catalyst SD-WAN and IOS XE software, and the detail that should decide where they land in your queue is the severity: three at CVSS 9.9, plus a fourth command-injection bug rated 9.8. The updates arrived in an August 5, 2026 hardening release and were reported by The Hacker News the next day, less than a week after Cisco warned of an actively exploited firewall-management zero-day — a run of disclosures that keeps the company's networking portfolio in the spotlight.
The headline is the count; the number that sets priority is the score. Three Catalyst SD-WAN vulnerabilities — CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 — each carry a CVSS score of 9.9, and a separate IOS XE command-injection flaw, CVE-2026-20272, is rated 9.8. Cisco says the flaws surfaced during internal security testing — including, by its own account, the use of frontier AI models — and are not known to be exploited in the wild. That framing matters for triage: a maximum-severity rating on a widely deployed networking platform is the kind of detail that reorders a patch queue even when no exploitation has been reported.
| CVE | Product | CVSS | Type |
|---|---|---|---|
| CVE-2026-20303 | Cisco Catalyst SD-WAN | 9.9 | Improper input validation (path traversal) |
| CVE-2026-20304 | Cisco Catalyst SD-WAN | 9.9 | Improper access control |
| CVE-2026-20310 | Cisco Catalyst SD-WAN | 9.9 | Improper link resolution before file access |
| CVE-2026-20272 | Cisco IOS XE | 9.8 | Command injection |
| CVE-2026-20267 | Cisco IOS XE | 9.0 | Improper access control |
What Cisco Fixed
The 12 flaws split across two product lines. On the Catalyst SD-WAN side, Cisco lists five vulnerabilities, led by the three rated 9.9: CVE-2026-20303, an improper input validation issue that also covers path traversal; CVE-2026-20304, an improper access control flaw; and CVE-2026-20310, an improper link resolution before file access. Two lower-severity SD-WAN bugs round out that group — CVE-2026-20312 (CVSS 8.8, cleartext storage of sensitive information) and CVE-2026-20313 (CVSS 7.7). Cisco notes the SD-WAN flaws affect Catalyst SD-WAN Software regardless of device configuration.
The IOS XE set covers seven flaws, and the one to watch is CVE-2026-20272, a 9.8-rated command-injection vulnerability (improper neutralization of special elements). It is joined by CVE-2026-20267, an improper access control flaw rated 9.0, and five more in the 8.6 band spanning buffer overflows, input validation, and control-flow problems. Cisco says these affect IOS XE Software running in autonomous or controller mode.
One related fix is worth flagging separately. Alongside the SD-WAN and IOS XE bundle, Cisco patched CVE-2026-20200 (CVSS 8.8), a command-injection flaw dubbed "CIMCown" in the web interface of its Integrated Management Controller — and here a proof-of-concept exploit is already public. That controller sits beneath the operating system, close to firmware and boot, so a root compromise there is unusually hard to detect. If you run affected server hardware, this one deserves attention on par with the 9.9s, even though it is not part of the headline 12.
What to Verify
Because nothing here is under active attack, this is a scheduling exercise — and the score gives you the order. Confirm affected releases against Cisco's Catalyst SD-WAN hardening advisory and its IOS XE counterpart, then map each instance to the right fixed build. For Catalyst SD-WAN, Cisco's fixed trains include 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2; anything earlier than 20.9 has to migrate to a fixed release. For IOS XE, the fixed versions are 17.9.10, 17.12.8, 17.15.6, 17.18.4 (and 17.18.4a), and 26.1.2.
Two operational notes matter for scoping. The SD-WAN flaws apply regardless of device configuration, so a "we don't use that feature" assumption does not remove exposure; the IOS XE flaws apply specifically to autonomous or controller mode, so how the device is deployed determines whether it is in scope. Neither set appears on CISA's Known Exploited Vulnerabilities catalog at publication — consistent with Cisco's statement that none are known to be exploited — which is the status worth re-checking, because a KEV addition would convert this from a scheduled patch into a deadline. For federal civilian agencies that would change the timeline from internal policy to a binding directive; for everyone else it is the clearest signal that a flaw has moved from theoretical to actively abused. It is the same escalation that followed Cisco's earlier Catalyst SD-WAN Manager zero-day, which moved onto KEV once exploitation was confirmed.
The practical verification is more than a version bump. Catalyst SD-WAN and IOS XE frequently sit at the routing and management core of a network, often spanning multiple release trains across a single estate, so the inventory step — which instances run which train, and which fixed build each needs — is where this work actually lives. A remediation ledger that reads "SD-WAN: patched" is the failure mode; the one that reads at the granularity of individual CVE-to-build mappings is what lets a team answer, quickly, whether they are covered when the next advisory lands.
My Read
The absence of exploitation is the reason to act deliberately, not the reason to wait. Three flaws at CVSS 9.9 in a management-and-routing layer as widely deployed as Catalyst SD-WAN is exactly the profile attackers reverse-engineer from a patch, and Cisco's own framing — that these were found partly with AI-assisted testing — suggests the discovery pace on this portfolio is not slowing. The disciplined move is to treat the three 9.9s and the 9.8 as this week's work, confirm the fixed builds actually landed on every instance rather than assuming one representative node speaks for the fleet, and keep a standing eye on CISA KEV. A clean exploitation status today is a window to patch on your own schedule; it is not a guarantee the window stays open.