Cisco Patches Critical SD-WAN Vulnerabilities, Update Now
Key Takeaways Cisco has released critical software updates for its Catalyst SD-WAN Software. Multiple high-severity vulnerabilities, some with CVSS scores of 9.9, were identified during an internal...
Key Takeaways
- Cisco has released critical software updates for its Catalyst SD-WAN Software.
- Multiple high-severity vulnerabilities, some with CVSS scores of 9.9, were identified during an internal security review.
- All deployment modes of Catalyst SD-WAN Software are affected, including on-premises, cloud-pro, Cisco-managed, and government deployments.
- No active exploitation has been detected, and the flaws were discovered proactively by Cisco’s engineering team.
- Immediate patching is strongly recommended, as no workarounds exist, and some affected versions require migration to a supported release.
Cisco Issues Urgent Patches for Critical SD-WAN Vulnerabilities
Cisco has released crucial software hardening updates for its Catalyst SD-WAN Software following an extensive internal security assessment that uncovered several critical vulnerabilities within the platform. The proactive review by Cisco’s own engineering team revealed these serious flaws, though the company has confirmed no evidence of active exploitation in the wild.
Table Of Content
Despite the absence of current attacks, the severe nature of these issues necessitates immediate attention. Administrators overseeing Catalyst SD-WAN deployments in any configuration are strongly advised to prioritize patching their systems without delay.
Streamlined Disclosure for Critical Flaws
In an effort to simplify the patching process for customers, Cisco opted to group related vulnerabilities by their underlying Common Weakness Enumeration (CWE) category, assigning a single CVE identifier to each group rather than separate advisories for individual bugs. Several of the most severe issues carry a CVSS score of 9.9, indicating an almost maximum potential impact.
Specifically, Notably, Cisco disclosed that these flaws were identified using a combination of traditional internal testing methods and advanced AI models, highlighting a new frontier in enterprise security research.
Understanding the Key Vulnerabilities
Three primary vulnerabilities stand out for their critical severity:
- CVE-2026-20303, rated 9.9, addresses improper input validation. This category encompasses related weaknesses such as path traversal and external control of file paths, which could allow attackers to manipulate system files.
- CVE-2026-20304, also rated 9.9, pertains to improper access control. This covers issues related to authorization, authentication, and privilege bypasses, potentially enabling unauthorized access or elevation.
- CVE-2026-20310, another 9.9 rated flaw, involves improper link resolution before file access. This type of vulnerability can be exploited by attackers to manipulate symbolic links, gaining access to unintended or restricted files.
Rounding out the advisory, CVE-2026-20312, with a CVSS score of 8.8, relates to the cleartext storage of sensitive information. This means credentials or other critical data could be exposed if the underlying system is compromised. Finally, CVE-2026-20313, scoring 7.7, involves improper validation of a specified quantity in input, representing a less severe but still significant weakness.
Widespread Impact Across Deployment Models
The vulnerabilities affect all deployment models of Cisco Catalyst SD-WAN Software, irrespective of device configuration. This includes on-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud environments, and Cisco SD-WAN for Government under FedRAMP. Cisco has explicitly stated that no configuration setting or feature toggle can mitigate exposure, making this a broad-reaching concern for organizations relying on Cisco’s SD-WAN infrastructure.
Cisco has confirmed that no workarounds are available for any of these vulnerabilities, making software upgrades the sole viable remediation path. Organizations currently running Catalyst SD-WAN releases older than 20.9 must migrate to a supported version, as those branches will not receive direct patches. Fixed builds include 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2, depending on the specific branch in use. Several affected releases, such as 20.11, 20.13, 20.14, and 20.16, have already reached their End of Software Maintenance, prompting Cisco to urge customers on these versions to transition to a currently supported release rather than attempting a point fix.
For customers utilizing Cisco SD-WAN Cloud as a Cisco-managed service, no action is required, as the vendor has already applied the necessary fixes in Release 20.15.602 on the backend. Administrators can verify their remediation status via the Help function within their service GUI.
What You Should Do
- Immediately Review Your SD-WAN Versions: Check your current Cisco Catalyst SD-WAN Software release against Cisco’s official advisory.
- Plan for Upgrades: Schedule and perform necessary software upgrades to a fixed release (e.g., 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, 26.1.2).
- Migrate Unsupported Versions: If running releases older than 20.9 or those that have reached End of Software Maintenance (e.g., 20.11, 20.13), plan a migration to a fully supported, patched release.
- Verify Cloud Service Status: If using Cisco SD-WAN Cloud as a Cisco-managed service, confirm the fix has been applied (Release 20.15.602) through the service GUI.
- Prioritize Internet-Facing Systems: Give immediate priority to patching any internet-facing SD-WAN infrastructure due to the elevated risk of exposure.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.