Ethical Hacking News
Cisco has released patches to address multiple critical security vulnerabilities in its Catalyst SD-WAN software and IOS XE software. The patches aim to prevent exploitation of known vulnerabilities affecting both software systems. Customers are advised to install the latest updates for optimal protection. Stay ahead of emerging threats with the latest news, expert insights, exclusive resources, and strategies from industry leaders. Get the latest news in your inbox.
Cisco Systems has released security patches to address multiple critical vulnerabilities in its Catalyst SD-WAN software and IOS XE software. The vulnerabilities affect devices regardless of configuration, with CVSS scores ranging from 7.7 to 9.9. The patches have been applied to the following versions of Cisco Catalyst SD-WAN Software: 20.9, 20.10, 20.111, 20.12, 20.131, and 26.1. Similar patches have been released for IOS XE Software, addressing improper access control, command injection, and input validation vulnerabilities. A high-severity security flaw has also been addressed in the web-based management interface of Integrated Management Controller (IMC).
Cisco Systems has recently released a series of security patches aimed at addressing multiple critical vulnerabilities in its Catalyst SD-WAN software and IOS XE software, respectively. According to the company's official statement, these vulnerabilities were identified through internal security testing using existing testing processes as well as frontier AI models, and are not known to be actively exploited at this time.
The vulnerabilities affecting the Catalyst SD-WAN Software, which impact Cisco Catalyst SD-WAN Software regardless of device configuration, have been assigned the following CVE identifiers:
* CVE-2026-20303 (CVSS score: 9.9) - An improper input validation vulnerability (which also covers path traversals)
* CVE-2026-20304 (CVSS score: 9.9) - An improper access control vulnerability
* CVE-2026-20310 (CVSS score: 9.9) - An improper link resolution before file access vulnerability
* CVE-2026-20312 (CVSS score: 8.8) - A cleartext storage of sensitive information vulnerability
* CVE-2026-20313 (CVSS score: 7.7) - An improper validation of specified quantity in input
These vulnerabilities have been addressed in the following versions of Cisco Catalyst SD-WAN Software:
* 20.9 (Fixed in 20.9.10)
* 20.10 (Fixed in 20.12.8.1)
* 20.111 (Fixed in 20.12.8.1)
* 20.12 (Fixed in 20.12.8.1)
* 20.131 (Fixed in 20.15.6)
* 20.141 (Fixed in 20.15.6)
* 20.15 (Fixed in 20.15.6)
* 20.161 (Fixed in 20.18.4)
* 20.18 (Fixed in 20.18.4)
* 26.1 (Fixed in 26.1.2)
On the other hand, the vulnerabilities affecting the IOS XE Software relate to improper access control, command injection, and improper input validation, and have been assigned the following CVE identifiers:
* CVE-2026-20267 (CVSS score: 9.0) - An improper access control vulnerability
* CVE-2026-20268 (CVSS score: 8.6) - A set of buffer overflow and out-of-bounds write vulnerabilities
* CVE-2026-20269 (CVSS score: 8.6) - An improper control of a resource through its lifetime vulnerability
* CVE-2026-20270 (CVSS score: 8.6) - An incorrect calculation vulnerability (which also covers arithmetic or numeric conversion errors including integer overflow, underflow, and truncation)
* CVE-2026-20271 (CVSS score: 8.6) - An insufficient control flow management vulnerability (which also covers infinite loops, uncontrolled recursion, and race conditions)
* CVE-2026-20272 (CVSS score: 9.8) - An improper neutralization of special elements vulnerability (which also covers command, operating system, and argument injection)
* CVE-2026-20273 (CVSS score: 8.6) - An improper input validation vulnerability (which also covers path traversals)
These vulnerabilities have been addressed in the following versions of Cisco IOS XE Software:
* 17.9 (Fixed in 17.9.10)
* 17.12 (Fixed in 17.12.8)
* 17.15 (Fixed in 17.15.6)
* 17.18 (Fixed in 17.18.4 and 17.18.4a)
* 26.1 (Fixed in 26.1.2)
It's worth noting that Cisco has also shipped fixes to address a high-severity security flaw in the web-based management interface of Integrated Management Controller (IMC), which has been assigned the CVE identifier CVE-2026-20200.
This vulnerability, also known as CVE-2026-20200 aka CIMCown, has a CVSS score of 8.8 and allows an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.
The disclosure comes less than a week after Cisco warned of active exploitation of CVE-2026-20316 (CVSS score: 5.3), a vulnerability in Cisco Secure Firewall Management Center (FMC) Software that could allow a low-privilege account to access sensitive data within susceptible systems.
As with the previous vulnerabilities, it's recommended that customers apply the necessary updates for optimal protection against these security issues.
Related Information:
https://www.ethicalhackingnews.com/articles/Cisco-Addresses-Multiple-Critical-Security-Vulnerabilities-in-SD-WAN-and-IOS-XE-Software-ehn.shtml
https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html
https://utopiats.com/blog/cisco-patches-12-sd-wan-and-ios-xe-flaws-including-three-98-cvss-score-bugs
https://nvd.nist.gov/vuln/detail/CVE-2026-20303
https://www.cvedetails.com/cve/CVE-2026-20303/
https://nvd.nist.gov/vuln/detail/CVE-2026-20304
https://www.cvedetails.com/cve/CVE-2026-20304/
https://nvd.nist.gov/vuln/detail/CVE-2026-20310
https://www.cvedetails.com/cve/CVE-2026-20310/
https://nvd.nist.gov/vuln/detail/CVE-2026-20312
https://www.cvedetails.com/cve/CVE-2026-20312/
https://nvd.nist.gov/vuln/detail/CVE-2026-20313
https://www.cvedetails.com/cve/CVE-2026-20313/
https://nvd.nist.gov/vuln/detail/CVE-2026-20267
https://www.cvedetails.com/cve/CVE-2026-20267/
https://nvd.nist.gov/vuln/detail/CVE-2026-20268
https://www.cvedetails.com/cve/CVE-2026-20268/
https://nvd.nist.gov/vuln/detail/CVE-2026-20269
https://www.cvedetails.com/cve/CVE-2026-20269/
https://nvd.nist.gov/vuln/detail/CVE-2026-20270
https://www.cvedetails.com/cve/CVE-2026-20270/
https://nvd.nist.gov/vuln/detail/CVE-2026-20271
https://www.cvedetails.com/cve/CVE-2026-20271/
https://nvd.nist.gov/vuln/detail/CVE-2026-20272
https://www.cvedetails.com/cve/CVE-2026-20272/
https://nvd.nist.gov/vuln/detail/CVE-2026-20273
https://www.cvedetails.com/cve/CVE-2026-20273/
https://nvd.nist.gov/vuln/detail/CVE-2026-20200
https://www.cvedetails.com/cve/CVE-2026-20200/
Published: Fri Aug 7 03:56:13 2026 by llama3.2 3B Q4_K_M