Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Critical 9.9 CVSS Score Bugs
Cisco has released critical security updates for its Catalyst SD-WAN and IOS XE Software, addressing 12 vulnerabilities, three of which carry a near-perfect CVSS score of 9.9.

Cisco has issued urgent patches for a significant number of vulnerabilities affecting its widely used Catalyst SD-WAN and IOS XE Software. The updates address a total of 12 security flaws, with three of them rated as critical, carrying a CVSS score of 9.9, indicating a severe risk of exploitation.
These vulnerabilities were discovered during internal security testing, which included the use of advanced AI models. Cisco has stated that these flaws are not currently known to be actively exploited in the wild, but strongly advises customers to apply the patches promptly to safeguard their networks.
The vulnerabilities impacting Cisco Catalyst SD-WAN Software are diverse, including improper input validation, path traversal, and access control issues. Specifically, CVE-2026-20303 and CVE-2026-20304, both with a CVSS score of 9.9, stem from improper input validation and access control respectively. Another critical flaw, CVE-2026-20310, also rated 9.9, involves improper link resolution before file access. Other vulnerabilities in this suite include cleartext storage of sensitive information and improper input validation, with CVSS scores ranging from 7.7 to 8.8.
Cisco has provided specific fixed versions for its Catalyst SD-WAN Software, covering releases from 20.9 up to 20.18, as well as version 26.1. Customers are urged to migrate to the latest fixed releases, such as 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2, or earlier versions if they are not yet on a supported release.
In parallel, Cisco has also addressed seven vulnerabilities in its IOS XE Software, which operates in autonomous or controller modes. These flaws include improper access control, command injection, and improper input validation. A particularly severe vulnerability, CVE-2026-20272, with a CVSS score of 9.8, involves improper neutralization of special elements, potentially allowing for command injection. Other IOS XE vulnerabilities range in severity, with CVSS scores from 8.6 to 9.0.
Fixed versions for IOS XE Software include 17.9.10, 17.12.8, 17.15.6, 17.18.4 (and 17.18.4a), and 26.1.2. The company emphasizes the importance of updating to these patched versions to mitigate the risks associated with these critical flaws.
In addition to these extensive patches, Cisco also released a fix for a high-severity vulnerability (CVE-2026-20200, CVSS 8.8) in the web-based management interface of its Integrated Management Controller (IMC). This flaw, for which a proof-of-concept exploit is available, could allow an authenticated attacker to execute arbitrary commands and elevate privileges to root. The discovery of this IMC vulnerability highlights the critical nature of securing management interfaces, as a compromise can lead to deep system access and persistence.
These disclosures follow closely on the heels of Cisco's warning about active exploitation of a separate vulnerability in its Secure Firewall Management Center (FMC) Software, underscoring a challenging period for Cisco product security. The breadth of vulnerabilities across multiple product lines necessitates a proactive approach from administrators to ensure all affected systems are updated.