Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access control bypass, unauthorized privilege escalation, and exposure of sensitive data.
The most severe vulnerabilities are CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each with a maximum CVSS v3.1 score of 9.9.
Critical Cisco SD-WAN Flaws
These vulnerabilities were found during Cisco’s internal security testing, which included assessments supported by advanced AI models.
At the time of publication, Cisco’s Product Security Incident Response Team (PSIRT) stated that there are no known public exploit disclosures or malicious exploitation concerning these specific CVEs. However, due to the widespread impact of these vulnerabilities and the lack of workarounds, rapid patching is crucial.
Cisco has assigned individual CVE identifiers to several underlying flaws based on their Common Weakness Enumeration (CWE) classes. This method aims to simplify disclosure and remediation.
However, it is important to note that the listed score for each CVE reflects the highest potential severity within that category, not necessarily a single independent vulnerability.
CVE-2026-20304 is particularly significant for enterprise defenders because it involves CWE-284, improper access control. This category includes weaknesses in authorization, authentication, privilege management, and bypass mechanisms.
A successful exploit could allow an attacker with low-level privileges to bypass security controls, potentially jeopardizing the confidentiality, integrity, and availability of an SD-WAN environment.
CVE-2026-20303 addresses improper input validation under the CWE-20 category. According to Cisco, this category includes failures in input validation, path traversal, and external control of file paths. Such weaknesses could provide attackers with a pathway to submit malicious input or manipulate file path handling in unexpected ways.
Meanwhile, CVE-2026-20310 deals with improper link resolution before file access, tracked under CWE-59. This type of vulnerability is often associated with errors in handling symbolic links, in which a process may be misled into accessing unintended files or resources.
Additionally, Cisco has fixed CVE-2026-20312, which relates to cleartext storage of sensitive information and has a rating of 8.8, as well as CVE-2026-20313, which concerns improper quantity validation and has a rating of 7.7.
The advisory affects all instances of Cisco Catalyst SD-WAN Software, regardless of device configuration. Impacted deployment types include on-premises environments, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud, and Cisco SD-WAN for Government deployments.
Cisco has confirmed that no configuration changes or temporary mitigations can address these vulnerabilities; organizations must upgrade to the fixed software releases.
The available updates include version 20.9.10 for the 20.9 train, 20.12.8.1 for versions 20.10 through 20.12, 20.15.6 for versions 20.13 through 20.15, 20.18.4 for versions 20.16 and 20.18, and 26.1.2 for the 26.1 release. Systems running versions earlier than 20.9 must migrate to a supported, fixed release.
Customers using Cisco-managed SD-WAN Cloud have already received remediation through release 20.15.602 and do not need to take any manual action. However, administrators should verify the service version and remediation status through the platform’s Help interface.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world





