Cisco patches multiple critical flaws affecting Catalyst SD-WAN and IOS XE Software

07 Aug 2026

As a part of its comprehensive internal security review, Cisco has released updates for multiple critical security vulnerabilities in SD-WAN and IOS XE Software.

 

According to Cisco, these flaws were discovered during its internal security testing. The company has urged customers to apply the updates for optimal protection.

 

Through this blog, we will understand what the flaws are about and some of the security actions that organizations can take to prevent/respond to the threat.

About the vulnerabilities

Vendor + component affected 

Potentially exposed environments 

CVSS Score 

CVEs 

About  

  

 

Cisco +  

 

Cisco Catalyst SD-WAN and Cisco IOS XE Software  

 

 

 

 

 

Enterprises, service providers, government agencies, and  organizations using impacted versions 

Up to 9.9 (Critical) 

  • CVE-2026-20303 
  • CVE-2026-20304 
  • CVE-2026-20310 
  • CVE-2026-20312 
  • CVE-2026-20313 
  • CVE-2026-20267 
  • CVE-2026-20268 
  • CVE-2026-20269 
  • CVE-2026-20270 
  • CVE-2026-20271 
  • CVE-2026-20272 
  • CVE-2026-20273 

 

The vulnerabilities fixed include command injection, path traversal, improper input validation, buffer overflow, access control, and race condition.  

What can attackers do with the vulnerabilities?

Attackers can exploit the vulnerabilities to:

 

  • Gain unauthorized access by bypassing authentication and access control mechanisms.
  • Execute arbitrary operating system commands on vulnerable Cisco devices.
  • Take complete control of affected Cisco Catalyst SD-WAN and IOS XE devices.
  • Make unauthorized modification or overwrite sensitive files through path traversal and file access flaws.
  • Alter router, SD-WAN, and network configurations.
  • Access sensitive credentials or configuration data stored in the device.
  • Trigger DoS conditions or crash network devices.
  • Execute malicious codes by exploiting buffer overflow and memory management flaws.
  • Establish persistent access by modifying device settings.
  • Deploy malicious payloads.
  • Laterally move within enterprise by using compromised network infrastructure.

SharkStriker’s recommendations

SharkStriker recommends implementing the following:

 

  • Identify the affected Cisco Catalyst SD-WAN and IOS XE devices.
  • Upgrade to the latest Cisco fixed software release.
  • Restrict access to management interfaces.
  • Regularly review Cisco security advisories and maintain supported software versions.
  • Immediately identify Cisco Catalyst SD-WAN and Cisco IOS XE devices running affected software versions.
  • Upgrade all affected devices to the latest Cisco fixed software release.
  • Restrict access to device management interfaces using ACLs, VPNs, and trusted administrative networks.
  • Disable unnecessary management services exposed to untrusted networks.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE