Cisco Patches 12 Catalyst SD-WAN and IOS XE Flaws, Three Rated CVSS 9.9

Cisco's newest hardening release patches 12 Catalyst SD-WAN and IOS XE flaws — three of them rated CVSS 9.9 and a fourth at 9.8. Cisco says none are exploited yet, which makes this a patch-priority call: take the criticals first, schedule the rest by exposure.

Share
Flat white line-art of a Cisco Catalyst SD-WAN router and an IOS XE switch under a shield, one flat red dot marking the criticals.

Cisco's newest hardening release reads as a patch-priority problem rather than a breach — but three of the twelve fixes sit at the very top of the severity scale.

Cisco has shipped fixes for 12 flaws across its Catalyst SD-WAN and IOS XE software, and the detail that should decide where they land in your queue is the severity: three at CVSS 9.9, plus a fourth command-injection bug rated 9.8. The updates arrived in an August 5, 2026 hardening release and were reported by The Hacker News the next day, less than a week after Cisco warned of an actively exploited firewall-management zero-day — a run of disclosures that keeps the company's networking portfolio in the spotlight.

The headline is the count; the number that sets priority is the score. Three Catalyst SD-WAN vulnerabilities — CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 — each carry a CVSS score of 9.9, and a separate IOS XE command-injection flaw, CVE-2026-20272, is rated 9.8. Cisco says the flaws surfaced during internal security testing — including, by its own account, the use of frontier AI models — and are not known to be exploited in the wild. That framing matters for triage: a maximum-severity rating on a widely deployed networking platform is the kind of detail that reorders a patch queue even when no exploitation has been reported.

CVE Product CVSS Type
CVE-2026-20303 Cisco Catalyst SD-WAN 9.9 Improper input validation (path traversal)
CVE-2026-20304 Cisco Catalyst SD-WAN 9.9 Improper access control
CVE-2026-20310 Cisco Catalyst SD-WAN 9.9 Improper link resolution before file access
CVE-2026-20272 Cisco IOS XE 9.8 Command injection
CVE-2026-20267 Cisco IOS XE 9.0 Improper access control

What Cisco Fixed

The 12 flaws split across two product lines. On the Catalyst SD-WAN side, Cisco lists five vulnerabilities, led by the three rated 9.9: CVE-2026-20303, an improper input validation issue that also covers path traversal; CVE-2026-20304, an improper access control flaw; and CVE-2026-20310, an improper link resolution before file access. Two lower-severity SD-WAN bugs round out that group — CVE-2026-20312 (CVSS 8.8, cleartext storage of sensitive information) and CVE-2026-20313 (CVSS 7.7). Cisco notes the SD-WAN flaws affect Catalyst SD-WAN Software regardless of device configuration.

The IOS XE set covers seven flaws, and the one to watch is CVE-2026-20272, a 9.8-rated command-injection vulnerability (improper neutralization of special elements). It is joined by CVE-2026-20267, an improper access control flaw rated 9.0, and five more in the 8.6 band spanning buffer overflows, input validation, and control-flow problems. Cisco says these affect IOS XE Software running in autonomous or controller mode.

One related fix is worth flagging separately. Alongside the SD-WAN and IOS XE bundle, Cisco patched CVE-2026-20200 (CVSS 8.8), a command-injection flaw dubbed "CIMCown" in the web interface of its Integrated Management Controller — and here a proof-of-concept exploit is already public. That controller sits beneath the operating system, close to firmware and boot, so a root compromise there is unusually hard to detect. If you run affected server hardware, this one deserves attention on par with the 9.9s, even though it is not part of the headline 12.

Patch Priority
Do first — the three CVSS 9.9s
CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 in Cisco Catalyst SD-WAN. Confirm the fixed build on every instance.
Next — the 9.8 and 9.0
CVE-2026-20272 (command injection) and CVE-2026-20267 (access control) in Cisco IOS XE, plus CIMCown / CVE-2026-20200 if you run Cisco server hardware — a public PoC exists.
Then — the rest, by exposure
The remaining SD-WAN (8.8, 7.7) and IOS XE (8.6-band) flaws. Schedule against how reachable each instance is, and re-check CISA KEV as you go.

What to Verify

Because nothing here is under active attack, this is a scheduling exercise — and the score gives you the order. Confirm affected releases against Cisco's Catalyst SD-WAN hardening advisory and its IOS XE counterpart, then map each instance to the right fixed build. For Catalyst SD-WAN, Cisco's fixed trains include 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2; anything earlier than 20.9 has to migrate to a fixed release. For IOS XE, the fixed versions are 17.9.10, 17.12.8, 17.15.6, 17.18.4 (and 17.18.4a), and 26.1.2.

Two operational notes matter for scoping. The SD-WAN flaws apply regardless of device configuration, so a "we don't use that feature" assumption does not remove exposure; the IOS XE flaws apply specifically to autonomous or controller mode, so how the device is deployed determines whether it is in scope. Neither set appears on CISA's Known Exploited Vulnerabilities catalog at publication — consistent with Cisco's statement that none are known to be exploited — which is the status worth re-checking, because a KEV addition would convert this from a scheduled patch into a deadline. For federal civilian agencies that would change the timeline from internal policy to a binding directive; for everyone else it is the clearest signal that a flaw has moved from theoretical to actively abused. It is the same escalation that followed Cisco's earlier Catalyst SD-WAN Manager zero-day, which moved onto KEV once exploitation was confirmed.

The practical verification is more than a version bump. Catalyst SD-WAN and IOS XE frequently sit at the routing and management core of a network, often spanning multiple release trains across a single estate, so the inventory step — which instances run which train, and which fixed build each needs — is where this work actually lives. A remediation ledger that reads "SD-WAN: patched" is the failure mode; the one that reads at the granularity of individual CVE-to-build mappings is what lets a team answer, quickly, whether they are covered when the next advisory lands.

My Read

The absence of exploitation is the reason to act deliberately, not the reason to wait. Three flaws at CVSS 9.9 in a management-and-routing layer as widely deployed as Catalyst SD-WAN is exactly the profile attackers reverse-engineer from a patch, and Cisco's own framing — that these were found partly with AI-assisted testing — suggests the discovery pace on this portfolio is not slowing. The disciplined move is to treat the three 9.9s and the 9.8 as this week's work, confirm the fixed builds actually landed on every instance rather than assuming one representative node speaks for the fleet, and keep a standing eye on CISA KEV. A clean exploitation status today is a window to patch on your own schedule; it is not a guarantee the window stays open.

Primary Documents

Read more