{"id":2256,"date":"2026-08-06T19:37:38","date_gmt":"2026-08-06T19:37:38","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2256"},"modified":"2026-08-06T19:37:38","modified_gmt":"2026-08-06T19:37:38","slug":"cisco-patches-12-sd-wan-and-ios-xe-flaws-including-three-9-8-cvss-score-bugs","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2256","title":{"rendered":"Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 06, 2026<\/span><\/span><span class=\"p-tags\">Network Security \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgzkSwdiUeH8rB-KgSkEXrT-oNL19IyghM7Ks8UDOedxPYB5czgwO8pXNf0YUt7OHqAbRRDJkRvJffzJ0lfpEdqfLn-w-Bc9pwOa_1FNJjJkrVbD-diaZu9HRFqAlOBWogXEsZ4sSFRDW-HYmsaUmVD98QGQoyq2rHep_dwDa5ueafTUO0Lh6zsA-Czd3he\/s1700-e365\/cisco-flaws.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cisco has <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-notice-L4XfJg8S\" target=\"_blank\">rolled out updates<\/a> to address multiple critical security vulnerabilities impacting <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-sdwan-faLcR3K\" target=\"_blank\">Catalyst SD-WAN<\/a> and <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-iosxe-V8NMuMZJ\" target=\"_blank\">IOS XE Software<\/a> as part of a comprehensive internal security review.<\/p>\n<p>The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.<\/p>\n<p>\u00abThese vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models [&#8230;] and are not known to be actively exploited,\u00bb Cisco said, urging customers to apply the necessary updates for optimal protection.<\/p>\n<p>The vulnerabilities impacting Catalyst SD-WAN Software are listed below &#8211;<\/p>\n<ul>\n<li><strong>CVE-2026-20303<\/strong> (CVSS score: 9.9) &#8211; An improper input validation vulnerability (which also covers path traversals)<\/li>\n<li><strong>CVE-2026-20304<\/strong> (CVSS score: 9.9) &#8211; An improper access control vulnerability <\/li>\n<li><strong>CVE-2026-20310<\/strong> (CVSS score: 9.9) &#8211; An improper link resolution before file access vulnerability<\/li>\n<li><strong>CVE-2026-20312<\/strong> (CVSS score: 8.8) &#8211; A cleartext storage of sensitive information vulnerability<\/li>\n<li><strong>CVE-2026-20313<\/strong> (CVSS score: 7.7) &#8211; An improper validation of specified quantity in input<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The issues have been addressed in the following versions of Cisco Catalyst SD-WAN Software &#8211;<\/p>\n<p><a name=\"more\"\/><\/p>\n<ul>\n<li>20.9 (Fixed in 20.9.10)<\/li>\n<li>20.10 (Fixed in 20.12.8.1)<\/li>\n<li>20.111 (Fixed in 20.12.8.1)<\/li>\n<li>20.12 (Fixed in 20.12.8.1)<\/li>\n<li>20.131 (Fixed in 20.15.6)<\/li>\n<li>20.141 (Fixed in 20.15.6)<\/li>\n<li>20.15 (Fixed in 20.15.6)<\/li>\n<li>20.161 (Fixed in 20.18.4)<\/li>\n<li>20.18 (Fixed in 20.18.4)<\/li>\n<li>26.1 (Fixed in 26.1.2)<\/li>\n<li>Earlier than 20.9 (Migrate to a fixed release)<\/li>\n<\/ul>\n<p>The vulnerabilities impacting IOS XE Software relate to improper access control, command injection, and improper input validation &#8211;<\/p>\n<ul>\n<li><strong>CVE-2026-20267<\/strong> (CVSS score: 9.0) &#8211; An improper access control vulnerability<\/li>\n<li><strong>CVE-2026-20268<\/strong> (CVSS score: 8.6) &#8211; A set of buffer overflow and out-of-bounds write vulnerabilities<\/li>\n<li><strong>CVE-2026-20269<\/strong> (CVSS score: 8.6) &#8211; An improper control of a resource through its lifetime vulnerability<\/li>\n<li><strong>CVE-2026-20270<\/strong> (CVSS score: 8.6) &#8211; An incorrect calculation vulnerability (which also covers arithmetic or numeric conversion errors including integer overflow, underflow, and truncation)<\/li>\n<li><strong>CVE-2026-20271<\/strong> (CVSS score: 8.6) &#8211; An insufficient control flow management vulnerability (which also covers infinite loops, uncontrolled recursion, and race conditions)<\/li>\n<li><strong>CVE-2026-20272<\/strong> (CVSS score: 9.8) &#8211; An improper neutralization of special elements vulnerability (which also covers command, operating system, and argument injection)<\/li>\n<li><strong>CVE-2026-20273<\/strong> (CVSS score: 8.6) &#8211; An improper input validation vulnerability (which also covers path traversals)<\/li>\n<\/ul>\n<p>The set of seven flaws has been addressed in the following versions of Cisco IOS XE Software &#8211;<\/p>\n<ul>\n<li>17.9 (Fixed in 17.9.10)<\/li>\n<li>17.12 (Fixed in 17.12.8)<\/li>\n<li>17.15 (Fixed in 17.15.6)<\/li>\n<li>17.18 (Fixed in 17.18.4 and 17.18.4a)<\/li>\n<li>26.1 (Fixed in 26.1.2)<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Separately, Cisco also <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cimc-arg-inject-upSHdMfU\" target=\"_blank\">shipped fixes<\/a> to address a high-severity security flaw in the web-based management interface of Integrated Management Controller (IMC) (CVE-2026-20200) for which it acknowledged a <a href=\"https:\/\/github.com\/NSIDE-ATTACK-LOGIC\/CIMCown\" target=\"_blank\">proof-of-concept (PoC) exploit<\/a> is available.<\/p>\n<ul>\n<li><strong>CVE-2026-20200<\/strong> (CVSS score: 8.8) &#8211; An improper validation of user-supplied input that could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.<\/li>\n<li><strong>CVE-2026-20288<\/strong> (CVSS score: 6.5) &#8211; An improper validation of user-supplied input that could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.<\/li>\n<\/ul>\n<p>\u00abOne should be clear about what a compromise of the IMC means: the controller sits in a position where it can influence the BIOS and SecureBoot and interact with the operating system above it,\u00bb security researcher Christoph Peil, who discovered and reported CVE-2026-20200, <a href=\"https:\/\/www.nsideattacklogic.de\/en\/cisco-imc-when-remote-management-becomes-a-backdoor-cve-2026-20200\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>\u00abAn attacker who gains root here can thereby nest themselves deeply and persistently in the system \u2013 far below what classic protective measures such as EDR solutions at the operating-system level can even see. The trust anchor of the entire server hardware is thus compromised.\u00bb<\/p>\n<p>The disclosure comes less than a week after the network equipment company warned of active exploitation of CVE-2026-20316 (CVSS score: 5.3), a vulnerability in Cisco Secure Firewall Management Center (FMC) Software that could allow a low-privilege account to access sensitive data within susceptible systems.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 06, 2026Network Security \/ Vulnerability Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2257,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[809,124,497,11,584,428,57,2930,125],"class_list":["post-2256","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bugs","tag-cisco","tag-cvss","tag-flaws","tag-including","tag-ios","tag-patches","tag-score","tag-sdwan"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2256","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2256"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2256\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2257"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}