Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN
Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN
Read Time:3 Minute, 38 Second

Cisco has pushed out a fresh round of security updates for its Catalyst SD-WAN Software after its own engineers, not outside researchers, turned up a cluster of serious weaknesses during a routine internal review. The company says it has seen no sign that anyone is exploiting the bugs in the wild. That is the good news. The less comforting part is that three of the five newly disclosed vulnerabilities carry a CVSS score of 9.9, a hair below the maximum possible rating, and there is no configuration workaround for any of them.

Five Bugs, One Coordinated Advisory

Rather than publishing a separate bulletin for every individual flaw, Cisco grouped the issues by the underlying weakness category and assigned a single CVE to each group. The approach is meant to make patching simpler for network teams juggling multiple advisories, but the underlying risk is still substantial.

  • CVE-2026-20303 (CVSS 9.9) covers improper input validation, including path traversal and external control of file paths.
  • CVE-2026-20304 (CVSS 9.9) bundles improper access control issues, spanning authentication, authorization, and privilege bypass weaknesses.
  • CVE-2026-20310 (CVSS 9.9) involves improper link resolution before file access, a bug class that lets an attacker manipulate symbolic links to reach files that should be off-limits.
  • CVE-2026-20312 (CVSS 8.8) relates to cleartext storage of sensitive information, meaning credentials or secrets could be exposed if a device is compromised.
  • CVE-2026-20313 (CVSS 7.7) stems from improper validation of a specified quantity in input, a comparatively minor but still notable issue.

Every Deployment Mode Is in Scope

What makes this advisory particularly broad is that the flaws touch Catalyst SD-WAN regardless of how it is deployed. On-premises installations, Cisco SD-WAN Cloud-Pro, Cisco-managed cloud environments, and even Cisco SD-WAN for Government running under FedRAMP are all affected. No feature toggle or configuration choice exempts a device from exposure, which puts a wide swath of enterprise and government networks in the blast radius.

Cisco has been direct about the lack of alternatives: there is no mitigation short of upgrading. Organizations running any release earlier than 20.9 will need to move to a currently supported branch entirely, since those older versions will not receive a patch at all. Several in-between releases, including 20.11, 20.13, 20.14, and 20.16, have already hit end of software maintenance, so Cisco is steering customers toward a fully supported version rather than a narrow point fix.

Which Versions Actually Fix the Problem

The patched builds vary depending on which branch a network is currently running: 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2. Customers relying on Cisco’s fully managed SD-WAN Cloud service do not need to do anything themselves, since Cisco has already rolled the fix into the backend as part of Release 20.15.602. Administrators on that managed offering can confirm their remediation status through the Help function inside the service’s own GUI.

An AI-Assisted Discovery

One detail stands out in Cisco’s writeup: the company says the vulnerabilities were found through a mix of conventional internal testing and frontier AI models. That is a notable signal about where enterprise vulnerability research is heading, and it may partly explain why five distinct, serious issues surfaced together rather than being caught one at a time over a longer stretch.

Why This Still Deserves Urgency

The absence of known exploitation is not the same as safety. Once an advisory like this goes public, the technical detail packed into CVE descriptions gives capable attackers a head start on reverse-engineering a working exploit, particularly for scores this close to the ceiling. SD-WAN infrastructure typically sits at the center of an organization’s wide-area network, making it a high-value target if any of these bugs turn into a practical exploit chain, especially the access-control and file-path weaknesses.

Network and security teams should treat this as a priority patching cycle rather than something to fold into the next scheduled maintenance window. Because there is no workaround, the only path to closing the exposure is confirming the current SD-WAN release against Cisco’s advisory and scheduling the upgrade, particularly for internet-facing deployments where the cost of delay is highest.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN, use the discussion on Forum.

>> forum community

Comments

Leave a Reply