Breaking
SecurityDeveloping Story

Cisco Addresses Critical Device Flaws

Cisco has released security patches addressing two dozen vulnerabilities across its product lines, including several critical defects.

··1 hour ago·2 min read
a close up of a network with wires connected to it
Photo by Albert Stoynov on Unsplash

Cisco issued a series of updates on Wednesday to address two dozen vulnerabilities affecting a range of its enterprise networking and security products. The patches target flaws identified within the company's Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC) platforms.

Catalyst SD-WAN Vulnerability Fixes

For the Catalyst SD-WAN platform, Cisco released five fixes. The company grouped the associated CVEs based on the underlying vulnerability class. Three of these identifiers, CVE-2026-20303, CVE-2026-20310, and CVE-2026-20304, carry a CVSS score of 9.9. These are classified as improper input validation, improper link resolution before file access, and improper access control.

The company also addressed two additional issues within the Catalyst SD-WAN suite. These are designated as CVE-2026-20312 and CVE-2026-20313, which are categorized as high-severity flaws involving cleartext storage of sensitive information and improper validation of specified quantity in input.

IOS XE Security Updates

Cisco implemented seven fixes for the IOS XE platform. Among these, CVE-2026-20272 has a CVSS score of 9.8, while CVE-2026-20267 holds a CVSS score of 9.0. These are identified as critical-severity command injection and improper access control defects. The remaining vulnerabilities affecting IOS XE are categorized as high-severity.

Critical FMC Authentication Bypass

The Secure Firewall Management Center (FMC) received a patch for CVE-2026-20079, which carries a CVSS score of 10. This is an authentication bypass vulnerability that permits remote, unauthenticated attackers to execute scripts and obtain root privileges.

An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.

— Cisco

Integrated Management Controller Risks

Cisco addressed high-severity defects in the Integrated Management Controller (IMC), as well as within IOS and IOS XE. Additionally, medium-severity bugs were patched in IMC, IOS XE, RoomOS, Catalyst SD-WAN Manager, and Terminal Service (TS) Agent.

CVE-2026-20200, which has a CVSS score of 8.8, is a high-severity improper validation of user-supplied input issue affecting the IMC. This vulnerability could be exploited remotely to execute arbitrary commands and gain root privileges. The issue affects UCS C-Series M7 and M8 Rack Servers in standalone mode. Cisco noted that proof-of-concept (PoC) code targeting this specific vulnerability exists.

Summary of Quantifiable Data

  • CVE-2026-20079: CVSS score of 10
  • CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310: CVSS score of 9.9
  • CVE-2026-20272: CVSS score of 9.8
  • CVE-2026-20267: CVSS score of 9.0
  • CVE-2026-20200: CVSS score of 8.8

Impact and Mitigation Steps

Cisco stated it is not aware of any of these vulnerabilities being exploited in the wild. Organizations utilizing these products can find additional information regarding these updates on the company's security advisories page. The breadth of these patches requires administrators to review their current software versions to determine if their specific hardware configurations are impacted by the newly disclosed vulnerabilities.

#cisco#vulnerabilities#patching#networking#cybersecurity

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories