Critical Flaws in Cisco’s SD-WAN and IOS XE Expose Businesses to Remote Attacks
Cisco has just released patches for two dozen vulnerabilities across its products, including critical-severity bugs in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The affected companies should take immediate action to protect their networks from potential attacks. These flaws could allow hackers to gain root access, execute scripts, and even compromise sensitive information.
The most worrying vulnerabilities are found in Cisco’s Catalyst SD-WAN, which has five critical-severity fixes for CVEs assigned to multiple weaknesses grouped by the underlying vulnerability class. Three of these CVEs – CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 – have a CVSS score of 9.9 and are described as improper input validation, improper access control, and improper link resolution before file access. This means that if an attacker were to exploit these vulnerabilities, they could gain unauthorized access to the system, modify data, or even execute malicious code.
The IOS XE received seven patches for CVEs grouped by their underlying vulnerability class. Two of them – CVE-2026-20272 and CVE-2026-20267 – are critical-severity flaws with a CVSS score of 9.8 and 9.0 respectively, describing command injection and improper access control defects. These vulnerabilities could allow hackers to inject malicious commands or gain unauthorized access to sensitive data.
Perhaps the most alarming vulnerability is found in FMC, which has a CVSS score of 10 for CVE-2026-20079. This critical authentication bypass flaw allows remote attackers to execute scripts and gain root privileges by sending crafted HTTP requests to an affected device. Cisco notes that this vulnerability could be exploited without any prior authentication.
Another high-severity issue in IMC (Integrated Management Controller) deserves special attention, as it affects UCS C-Series M7 and M8 Rack Servers in standalone mode. This vulnerability – CVE-2026-20200 with a CVSS score of 8.8 – is an improper validation of user-supplied input issue that could be exploited remotely to execute arbitrary commands and gain root privileges.
While Cisco claims that it is not aware of any exploits in the wild, the existence of proof-of-concept (PoC) code targeting this vulnerability should raise concerns for businesses using these products. It’s essential for companies to take immediate action and apply the available patches to protect their networks from potential attacks.
To mitigate these risks, businesses should:
* Immediately update all affected systems with the latest patches
* Ensure that access controls are in place to limit access to sensitive data
* Monitor network traffic for signs of malicious activity
* Consider conducting a thorough security audit to identify and address any other vulnerabilities
It’s crucial to stay vigilant and up-to-date on the latest cybersecurity threats, as attackers continually find new ways to exploit weaknesses. By taking proactive steps to protect their networks, businesses can minimize the risk of falling victim to these types of attacks.
Source: SecurityWeek — 2026-08-06