Cisco Fixes Critical Vulnerabilities in SD-WAN, IOS XE, and Secure Firewall

Cisco fixes critical vulnerabilities in SD-WAN, IOS XE, and Secure Firewall, including a CVSS 10.0 flaw. Urgent updates required for affected systems.

Cisco Fixes Critical Vulnerabilities in SD-WAN, IOS XE, and Secure Firewall
Vulnerabilities

Illustrative image generated with AI

Patches for About Two Dozen Vulnerabilities

Cisco has released security updates addressing about two dozen vulnerabilities across its products. The flaws range from critical to high and medium severity and affect several device and platform families.

The company says it has found no evidence that the vulnerabilities have been exploited in real-world attacks. Exact affected versions were not disclosed; administrators should consult the Cisco advisory for each product to determine which updates apply.

Most Severe Vulnerabilities

Catalyst SD-WAN

Cisco has fixed five vulnerabilities in Catalyst SD-WAN. Three have a CVSS score of 9.9:

  • CVE-2026-20303: insufficient input validation;
  • CVE-2026-20304: improper access control;
  • CVE-2026-20310: improper handling of links before file access.

The remaining two flaws are high severity:

  • CVE-2026-20312, involving the storage of sensitive information in plaintext;
  • CVE-2026-20313, caused by improper validation of the quantity specified in the input.

IOS XE

IOS XE receives fixes for seven vulnerabilities, including:

  • CVE-2026-20272, CVSS 9.8, a critical command injection vulnerability;
  • CVE-2026-20267, CVSS 9.0, a critical improper access control vulnerability.

The other five vulnerabilities in this group are high severity.

Secure Firewall Management Center

The highest-scoring flaw is CVE-2026-20079, rated CVSS 10.0. It affects Secure Firewall Management Center and allows an unauthenticated remote attacker to submit specially crafted HTTP requests.

The attack could lead to script and command execution, potentially resulting in root access. Because authentication can be bypassed, this vulnerability should be treated as a priority on systems exposed to untrusted networks.

Risks Affecting Integrated Management Controller and Other Products

Cisco has addressed CVE-2026-20200 in Integrated Management Controller. The vulnerability has a CVSS score of 8.8 and is rated high severity. An authenticated remote user can exploit insufficient input validation to execute arbitrary commands and obtain root privileges.

Proof-of-concept (PoC) code is already available for this vulnerability. It affects UCS C-Series M7 and M8 Rack Servers operating in standalone mode.

Cisco has also fixed high-severity vulnerabilities in IMC, IOS XE, and IOS. Additional medium-severity flaws affect IOS XE, TS Agent, Catalyst SD-WAN Manager, RoomOS, and IMC.

What Administrators Should Do

Available Cisco updates should be applied to all affected devices, prioritizing:

  1. CVE-2026-20079;
  2. the three Catalyst SD-WAN vulnerabilities with a CVSS score of 9.9;
  3. CVE-2026-20272 and CVE-2026-20267 in IOS XE;
  4. CVE-2026-20200 on standalone UCS C-Series M7 and M8 servers.

Until patches are applied, administrators should reduce exposure of management interfaces, monitor for anomalous HTTP requests, and look for unexpected command or script execution.

IMC administrators should also review access controls and check for UCS servers matching the affected models. Cisco advisories remain the authoritative source for confirming the availability and applicability of each fix.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →