TL;DR
Cisco patched five Cisco SD-WAN vulnerability issues in Catalyst SD-WAN Software. Three are Critical, with two scoring CVSS 9.9. Cisco found them internally and reports no active exploitation.
- Product: Cisco Catalyst SD-WAN Controller
- Vulnerabilities: 5 flaws (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313)
- Highest severity: 9.9 (Critical · CVSSv3)
- Worst impact: Catalyst SD-WAN Security Hardening Release - Input Validation
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-20303 | 9.9 | CWE-20 | — | Not exploited |
| CVE-2026-20304 | 9.9 | CWE-284 | — | Not exploited |
| CVE-2026-20310 | 9.1 | CWE-59 | — | Not exploited |
| CVE-2026-20312 | 8.8 | CWE-312 | — | Not exploited |
| CVE-2026-20313 | 7.7 | CWE-1284 | — | Not exploited |
Why This Cisco SD-WAN Vulnerability Matters
Catalyst SD-WAN routes traffic across enterprise and government networks. Therefore, a flaw here threatens the core of many corporate WANs. The bugs affect every deployment type, including on-prem, cloud, and FedRAMP government setups.
According to the official Cisco security advisory, the flaws affect the software regardless of device configuration.
How the Attacks Work
Cisco grouped the flaws by weakness class, then assigned one CVE to each. The two top bugs both score 9.9.
CVE-2026-20303: Input Validation
This flaw stems from improper input validation. It also covers path traversal and external path control.
CVE-2026-20304: Access Control
This bug breaks authorization and authentication. As a result, attackers may bypass privilege checks.
Other Fixed Flaws
CVE-2026-20310 (CVSS 9.1) involves improper link resolution before file access. Meanwhile, CVE-2026-20312 (8.8) exposes cleartext secrets, and CVE-2026-20313 (7.7) mishandles input quantity validation.
Affected Versions
The flaws hit Cisco Catalyst SD-WAN releases before the fixed builds. Cisco confirms no known exploitation in the wild and no public proof-of-concept.
Patch and Mitigation Steps
There are no workarounds, so patching is the only fix. Upgrade to a fixed release right away:
- 20.9 branch: upgrade to 20.9.10
- 20.10 through 20.12: upgrade to 20.12.8.1
- 20.13 through 20.15: upgrade to 20.15.6
- 20.16 and 20.18: upgrade to 20.18.4
- 26.1: upgrade to 26.1.2
Cloud-managed customers on Release 20.15.602 need no action. Older releases should migrate to a supported, fixed build.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.