Cisco Patches Critical Vulnerabilities in Catalyst SD-WAN Software
Cisco has released urgent patches for multiple critical vulnerabilities in its Catalyst SD-WAN Software, including flaws with CVSS scores of 9.9, affecting all deployment models.

Cisco has issued critical software updates for its Catalyst SD-WAN Software following the proactive discovery of several severe vulnerabilities by its internal security teams. The company has stated there is no current evidence of these flaws being exploited in the wild, but emphasizes the urgency for administrators to apply patches across all deployment models due to the high severity of the issues.
To streamline the disclosure and patching process, Cisco has grouped related vulnerabilities under single CVE identifiers based on their Common Weakness Enumeration (CWE) categories. The most critical vulnerabilities, CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each carry a CVSS score of 9.9. CVE-2026-20303 addresses improper input validation, including issues like path traversal and external control of file paths. CVE-2026-20304 covers improper access control, encompassing authorization, authentication, and privilege bypass weaknesses. CVE-2026-20310 relates to improper link resolution before file access, which could allow attackers to access unintended files.
Further vulnerabilities include CVE-2026-20312, rated 8.8, which involves the cleartext storage of sensitive information, potentially exposing credentials or other secrets. CVE-2026-20313, with a CVSS score of 7.7, stems from improper validation of specified quantities in input. These flaws collectively represent a significant risk to organizations utilizing Cisco's SD-WAN solutions.
The vulnerabilities affect all deployment models of Cisco Catalyst SD-WAN Software, including on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud environments, and Cisco SD-WAN for Government under FedRAMP. No specific configuration or feature setting provides immunity, making this advisory relevant to a broad range of enterprise and government customers.
Cisco has confirmed that there are no workarounds available for these vulnerabilities, making software upgrades the sole remediation path. Organizations running versions earlier than 20.9 must migrate to a supported, patched release, as older branches will not receive fixes. Specific patched releases include 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2, depending on the customer's current branch. Cisco advises customers on End of Software Maintenance releases to upgrade to a supported version rather than attempting a point fix.
For customers using Cisco SD-WAN Cloud under a Cisco-managed service, no action is required as Cisco has already applied the necessary fixes. These vulnerabilities were reportedly discovered using a combination of traditional testing and advanced AI models, highlighting the growing role of AI in vulnerability research. While no active exploitation has been reported, the high severity of these flaws makes them prime targets for future attacks once more details become public.
Organizations are strongly urged to consult Cisco's official advisory for detailed information on affected versions and fixed releases. Promptly scheduling and implementing software upgrades is crucial, especially for internet-facing SD-WAN infrastructure, to mitigate the significant risks associated with these critical security weaknesses.