Cisco Addresses Critical Device Flaws
Cisco has released security patches addressing two dozen vulnerabilities across its product lines, including several critical defects.
Cisco issued a series of updates on Wednesday to address two dozen vulnerabilities affecting a range of its enterprise networking and security products. The patches target flaws identified within the company's Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC) platforms.
Catalyst SD-WAN Vulnerability Fixes
For the Catalyst SD-WAN platform, Cisco released five fixes. The company grouped the associated CVEs based on the underlying vulnerability class. Three of these identifiers, CVE-2026-20303, CVE-2026-20310, and CVE-2026-20304, carry a CVSS score of 9.9. These are classified as improper input validation, improper link resolution before file access, and improper access control.
The company also addressed two additional issues within the Catalyst SD-WAN suite. These are designated as CVE-2026-20312 and CVE-2026-20313, which are categorized as high-severity flaws involving cleartext storage of sensitive information and improper validation of specified quantity in input.
IOS XE Security Updates
Cisco implemented seven fixes for the IOS XE platform. Among these, CVE-2026-20272 has a CVSS score of 9.8, while CVE-2026-20267 holds a CVSS score of 9.0. These are identified as critical-severity command injection and improper access control defects. The remaining vulnerabilities affecting IOS XE are categorized as high-severity.
Critical FMC Authentication Bypass
The Secure Firewall Management Center (FMC) received a patch for CVE-2026-20079, which carries a CVSS score of 10. This is an authentication bypass vulnerability that permits remote, unauthenticated attackers to execute scripts and obtain root privileges.
An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
— Cisco
Integrated Management Controller Risks
Cisco addressed high-severity defects in the Integrated Management Controller (IMC), as well as within IOS and IOS XE. Additionally, medium-severity bugs were patched in IMC, IOS XE, RoomOS, Catalyst SD-WAN Manager, and Terminal Service (TS) Agent.
CVE-2026-20200, which has a CVSS score of 8.8, is a high-severity improper validation of user-supplied input issue affecting the IMC. This vulnerability could be exploited remotely to execute arbitrary commands and gain root privileges. The issue affects UCS C-Series M7 and M8 Rack Servers in standalone mode. Cisco noted that proof-of-concept (PoC) code targeting this specific vulnerability exists.
Summary of Quantifiable Data
- CVE-2026-20079: CVSS score of 10
- CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310: CVSS score of 9.9
- CVE-2026-20272: CVSS score of 9.8
- CVE-2026-20267: CVSS score of 9.0
- CVE-2026-20200: CVSS score of 8.8
Impact and Mitigation Steps
Cisco stated it is not aware of any of these vulnerabilities being exploited in the wild. Organizations utilizing these products can find additional information regarding these updates on the company's security advisories page. The breadth of these patches requires administrators to review their current software versions to determine if their specific hardware configurations are impacted by the newly disclosed vulnerabilities.
Sources
- SecurityWeek Original source
- security advisories Also reporting
Continue Reading
AI Agent Frameworks Face Security Crisis
Researchers reveal that vulnerabilities in AI agent foundations allow prompt injection to bypass critical trust boundaries.
Chrome 151 Update Addresses 41 Security Flaws
Google has issued a new browser update addressing 41 critical and high-severity vulnerabilities across multiple platforms.
TrueBooker WordPress Plugin Critical Flaw
A critical authorization bypass vulnerability in the TrueBooker plugin allows unauthenticated attackers to reset passwords for any user, including administrators.