Vulnerabilities

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.

Cisco patches

Cisco on Wednesday rolled out patches for two dozen vulnerabilities across its products, including critical-severity bugs in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC).

For Catalyst SD-WAN, the company released five fixes, noting that the CVEs were assigned to multiple weaknesses grouped by the underlying vulnerability class.

Three of the CVEs, namely CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, have a CVSS score of 9.9 and are described as improper input validation, improper access control, and improper link resolution before file access.

The remaining two, CVE-2026-20312 and CVE-2026-20313, are high-severity flaws described as cleartext storage of sensitive information and improper validation of specified quantity in input.

IOS XE received seven fixes, and the assigned CVEs group multiple issues by their underlying vulnerability class.

Two of them, CVE-2026-20272 (CVSS score of 9.8) and CVE-2026-20267 (CVSS score of 9.0), are critical-severity command injection and improper access control defects, while the rest are high-severity flaws.

Advertisement. Scroll to continue reading.

FMC received patches for CVE-2026-20079 (CVSS score of 10), a critical authentication bypass that allows remote, unauthenticated attackers to execute scripts and gain root privileges.

“An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device,” Cisco notes.

The company also patched high-severity security defects in Integrated Management Controller (IMC), IOS XE, and IOS, and medium-severity bugs in IOS XE, Terminal Service (TS) Agent, Catalyst SD-WAN Manager, RoomOS, and IMC.

Of these, CVE-2026-20200 (CVSS score of 8.8) deserves special attention. It is a high-severity improper validation of user-supplied input issue in IMC that could be exploited remotely to execute arbitrary commands and gain root privileges.

While the flaw’s exploitation requires authentication, proof-of-concept (PoC) code targeting it exists, Cisco warns. The weakness affects UCS C-Series M7 and M8 Rack Servers in standalone mode.

Cisco says it is not aware of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s security advisories page.

Related: Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Related: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Related: N‑able Patches Vulnerability Exploited to Hack N-central Servers

Related: Ruby on Rails Patches Critical Vulnerability

Related Content

Vulnerabilities

Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.

Artificial Intelligence

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. 

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Vulnerabilities

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.

Endpoint Security

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.

Government

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

Vulnerabilities

Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.

Vulnerabilities

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.  

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version