Cisco has just released patches for a critical batch of vulnerabilities affecting several of its products, including SD-WAN, IOS XE, and FMC. The company has addressed two dozen issues, with some of them being so severe that they could allow attackers to gain root privileges on affected devices.
The most concerning vulnerability is in the Secure Firewall Management Center (FMC), where a critical authentication bypass flaw (CVE-2026-20079) allows remote, unauthenticated attackers to execute scripts and gain root access. This can be done by sending crafted HTTP requests to an affected device. According to Cisco, “a successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.” This is particularly alarming because it requires no authentication or credentials.
In addition to FMC, several other products have been patched for critical and high-severity vulnerabilities. The IOS XE has received seven fixes, including two with CVSS scores of 9.8 and 9.0 respectively. These are command injection and improper access control defects that could allow attackers to inject malicious commands or gain unauthorized access to sensitive areas.
The Catalyst SD-WAN also received five patches for vulnerabilities with high-severity flaws such as cleartext storage of sensitive information, improper validation of specified quantity in input, improper link resolution before file access, improper input validation and improper access control.
It’s worth noting that some of these vulnerabilities have already been discovered to be exploitable by proof-of-concept (PoC) code. The Integrated Management Controller (IMC), for example, has a high-severity flaw (CVE-2026-20200) that allows attackers to execute arbitrary commands and gain root privileges remotely.
Cisco assures users that it is not aware of any exploitation in the wild, but we should take this as a reminder to regularly check for updates and patches on our systems. These vulnerabilities could be exploited if left unpatched, leading to serious security breaches.
In light of these findings, it’s essential to ensure that all connected devices are running with the latest security patches installed. This will not only protect against known threats but also safeguard against potential zero-day exploits.
Source: SecurityWeek — 2026-08-06