Cisco releases fixes for 12 Catalyst SD-WAN and IOS XE vulnerabilities

Cisco has released security updates for 12 vulnerabilities affecting Catalyst SD-WAN Software and IOS XE Software, including three Catalyst SD-WAN flaws with CVSS scores of 9.9. The company also issued fixes for two Integrated Management Controller (IMC) vulnerabilities, one of which has a publicly available proof-of-concept exploit.
The Catalyst SD-WAN issues affect the software regardless of device configuration. IOS XE Software is affected when it operates in autonomous or controller mode. Cisco said the vulnerabilities were identified through its internal security testing processes and frontier AI models, and that none are known to be under active exploitation.
Critical Catalyst SD-WAN flaws
The three 9.9-rated Catalyst SD-WAN vulnerabilities are CVE-2026-20303, an improper input-validation issue that includes path traversal; CVE-2026-20304, an improper access-control flaw; and CVE-2026-20310, involving improper link resolution before file access. Cisco also addressed CVE-2026-20312, rated 8.8, for cleartext storage of sensitive information, and CVE-2026-20313, rated 7.7, involving validation of a specified quantity in input.
Fixed Catalyst SD-WAN releases include 20.9.10, 20.12.8.1, 20.15.6, 20.18.4 and 26.1.2, depending on the affected software train. Customers on releases earlier than 20.9 need to migrate to a fixed release.
IOS XE and IMC updates
For IOS XE, Cisco patched seven vulnerabilities spanning improper access control, buffer overflows and out-of-bounds writes, resource-lifetime control, calculation errors, control-flow management, command injection and input validation. CVE-2026-20272 is the highest-rated IOS XE issue at 9.8 and concerns insufficient neutralisation of special elements, including command, operating-system and argument injection.
IOS XE fixes are available in 17.9.10, 17.12.8, 17.15.6, 17.18.4 or 17.18.4a, and 26.1.2. The update cycle follows Cisco’s recent vulnerability activity, including Cisco vulnerabilities, ClickFix chains and AI-agent incidents that tracks Cisco flaws, ClickFix chains and rising AI-agent incidents across the security landscape.
Public PoC raises IMC priority
Cisco separately fixed CVE-2026-20200 in the web-based IMC management interface. Rated 8.8, it can allow an authenticated remote attacker with low privileges to execute arbitrary operating-system commands and elevate privileges to root. Cisco acknowledged that a proof of concept is available. CVE-2026-20288, rated 6.5, can similarly permit an authenticated administrator to execute commands and gain root privileges.
Researcher Christoph Peil, who reported CVE-2026-20200, said an IMC compromise can influence the BIOS and SecureBoot and interact with the operating system, placing an attacker below controls such as endpoint detection and response. Businesses should inventory affected SD-WAN, IOS XE and IMC deployments, match them to Cisco’s fixed releases, and prioritise maintenance where exposed management functions or IMC interfaces are in use.

