Cisco Catalyst SD-WAN and IOS XE: Critical Flaws Fixed
Cisco published a new set of security advisories, addressing vulnerabilities across Catalyst SD-WAN, IOS XE, Cisco Integrated Management Controller (IMC), RoomOS, Terminal Services Agent, and related products. The highest-priority updates affect platforms used for network control, routing, switching, and infrastructure management.
The most urgent issues are in Cisco Catalyst SD-WAN Software and Cisco IOS XE Software. Three SD-WAN vulnerabilities carry a CVSS score of 9.9, while one IOS XE vulnerability is rated CVSS 9.8. Cisco SD-WAN and IOS XE hardening issues were found through internal testing, including frontier AI models, and are not known to be actively exploited.
Which Cisco SD-WAN and IOS XE CVEs Were Published?
Cisco’s August 5, 2026 advisory set includes multiple security updates, but two hardening advisories stand out:
| Advisory | Key CVEs | Highest CVSS | Main affected product |
|---|---|---|---|
| Cisco Catalyst SD-WAN Software Security Hardening | CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313 | 9.9 | Catalyst SD-WAN Software |
| Cisco IOS XE Software Security Hardening | CVE-2026-20267 to CVE-2026-20273 | 9.8 | IOS XE in autonomous or controller mode |
| Cisco IMC Argument Injection Vulnerabilities | CVE-2026-20200, CVE-2026-20288 | 8.8 | Cisco Integrated Management Controller |
Cisco strongly recommends upgrading to the fixed software listed in the individual advisories. For the SD-WAN and IOS XE hardening advisories, Cisco lists no workarounds, making patching the main remediation path.
Which Cisco Vulnerabilities Should Teams Prioritize?
Security teams should prioritize the vulnerabilities that combine high severity with central network-control impact.
| CVE | CVSS | Product | Vulnerability class | Priority |
|---|---|---|---|---|
| CVE-2026-20303 | 9.9 | Catalyst SD-WAN Software | Improper input validation, including path traversal and external path control | Critical |
| CVE-2026-20304 | 9.9 | Catalyst SD-WAN Software | Improper access control | Critical |
| CVE-2026-20310 | 9.9 | Catalyst SD-WAN Software | Improper link resolution before file access | Critical |
| CVE-2026-20272 | 9.8 | IOS XE | Command, operating-system, and argument injection | Critical |
| CVE-2026-20267 | 9.0 | IOS XE | Improper access control | High priority |
| CVE-2026-20200 | 8.8 | Cisco IMC | Argument injection with root-level command execution impact | High priority |
Cisco notes that the CVSS score in the SD-WAN and IOS XE hardening advisories represents the maximum potential severity of the most impactful underlying issue within each CWE grouping.
What Are the Catalyst SD-WAN CVSS 9.9 Flaws?
Cisco’s Catalyst SD-WAN advisory covers five vulnerabilities affecting Catalyst SD-WAN Software, regardless of device configuration. The affected deployment types include on-premises deployments, SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud, and Cisco SD-WAN for Government.
The three highest-rated vulnerabilities are:
- CVE-2026-20303: Improper input validation, including path traversal and external path control
- CVE-2026-20304: Improper access control
- CVE-2026-20310: Improper link resolution before file access

Details of CVE-2026-20303 (SOCRadar Vulnerability Intelligence)
These issues should be treated as urgent because Catalyst SD-WAN components help coordinate enterprise connectivity across branches, cloud environments, and managed network paths.
Fixed releases include:
| Catalyst SD-WAN release | First fixed release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10 |
| 20.10, 20.11, 20.12 | 20.12.8.1 |
| 20.13, 20.14, 20.15 | 20.15.6 |
| 20.16, 20.18 | 20.18.4 |
| 26.1 | 26.1.2 |
Cisco says 20.11, 20.13, 20.14, and 20.16 have reached end of software maintenance. Cisco also addressed the issues in Cisco SD-WAN Cloud Release 20.15.602, with no customer action required for that cloud-based service.
What Is CVE-2026-20272 in IOS XE?
CVE-2026-20272 is the highest-rated vulnerability in the IOS XE hardening advisory. Cisco classifies it under CWE-74, covering improper neutralization of special elements such as command, operating-system, and argument injection. It carries a CVSS score of 9.8.

Details of CVE-2026-20272 (SOCRadar’s Vulnerability Intelligence)
The advisory applies to Cisco IOS XE Software when running in autonomous or controller mode, regardless of device configuration. Cisco’s evaluation covered IOS XE releases 17.9, 17.12, 17.15, 17.18, and 26.1.
Fixed releases include:
| IOS XE release | First fixed release |
|---|---|
| 17.9 | 17.9.10 |
| 17.12 | 17.12.8 |
| 17.15 | 17.15.6 |
| 17.18 | 17.18.4 or 17.18.4a |
| 26.1 | 26.1.2 |
Cisco also lists Snort rules 66897–66898 for this advisory. These detections may support monitoring, but they do not replace upgrading to fixed software.
Why Does Cisco IMC Also Matter?
Although the Cisco IMC advisory is not rated Critical, CVE-2026-20200 deserves attention because Cisco confirms that proof-of-concept (PoC) exploit code is available. Cisco says it is not aware of malicious use of the IMC vulnerabilities.
CVE-2026-20200 affects the web-based management interface of Cisco IMC. A remote attacker with low privileges could enter crafted input, execute commands on the underlying operating system, and elevate privileges to root. The issue affects UCS C-Series M7 and M8 Rack Servers in standalone mode when running vulnerable Cisco IMC releases.
Teams should include Cisco IMC exposure in triage, especially where management interfaces are reachable from broad internal networks or where low-privilege accounts exist.
What Other Cisco Issues Were Addressed?
Cisco’s advisory notice also lists additional vulnerabilities across IOS, IOS XE, Catalyst SD-WAN Manager, RoomOS, Terminal Services Agent, and IMC. These include denial-of-service, information disclosure, SNMP, firewall-rules bypass, and cross-site scripting issues with CVSS scores ranging from 4.3 to 8.8.
Lower-rated issues should remain in the remediation queue, but initial patching priority should focus on:
- Catalyst SD-WAN CVSS 9.9 vulnerabilities
- IOS XE CVE-2026-20272
- IOS XE CVE-2026-20267
- Cisco IMC CVE-2026-20200 where exposed or operationally sensitive
How Should Teams Triage the Cisco Advisory Update?
Security teams should use an asset-based process rather than treating the advisory bundle as one flat patch list.
Recommended actions include:
- Inventory Catalyst SD-WAN, IOS XE, Cisco IMC, RoomOS, Terminal Services Agent, and related appliances.
- Identify internet-facing or broadly reachable management interfaces.
- Confirm exact software trains and operating modes, especially for IOS XE.
- Upgrade Catalyst SD-WAN and IOS XE systems to the fixed releases listed by Cisco.
- Treat unsupported SD-WAN branches as migration priorities.
- Review administrative access, authentication logs, and configuration changes after remediation.
- Validate Cisco IMC exposure and patch CVE-2026-20200 where affected.
- Monitor Cisco advisory updates for exploitation status changes.
Cisco PSIRT hasn’t reported active exploitation, but centrally managed network infrastructure warrants prompt remediation regardless – attacker interest in high-severity Cisco advisories typically builds quickly after public disclosure.
How Can SOCRadar Help Prioritize Response?
Teams need to identify which Cisco assets are exposed, which software trains are affected, and whether exploitation signals change after disclosure.
SOCRadar’s Cyber Threat Intelligence helps security teams monitor new critical vulnerabilities, exploit alerts, affected technologies, and threat activity around products such as Catalyst SD-WAN, IOS XE, and Cisco IMC. This supports faster prioritization when a high-severity advisory gains public exploit activity or attacker interest.
Attack Surface Management (ASM) adds exposure context by helping organizations identify vulnerable software, exposed services, DNS records, expired certificates, undiscovered cloud assets, and public-facing infrastructure. It can also alert when a critical vulnerability is cross-referenced with exposed software assets.

SOCRadar’s Vulnerability Intelligence
For this Cisco advisory set, combining vulnerability intelligence with exposure visibility helps teams focus first on exposed SD-WAN infrastructure, critical IOS XE devices, and Cisco IMC interfaces that could expand risk if left unpatched.

