Exploits

Cisco SD-WAN IOS XE Vulnerabilities: Critical Patch Released

Published  ·  7 min read

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software. The patches are part of a comprehensive internal security review that used both existing testing processes and frontier AI models.

The Cisco SD-WAN IOS XE vulnerabilities affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.

The company said the vulnerabilities were found during internal security testing and are not known to be actively exploited. But the severity of the Cisco SD-WAN IOS XE vulnerabilities demands immediate attention. Let me walk through what is affected, what has been fixed, and what administrators need to do.

The Catalyst SD-WAN Vulnerabilities

Five Cisco SD-WAN IOS XE vulnerabilities impact Catalyst SD-WAN Software. Each carries a high CVSS score and could allow an attacker to compromise affected systems.

The Catalyst SD-WAN flaws are:

  • CVE-2026-20303 (CVSS: 9.9) - Improper input validation covering path traversals
  • CVE-2026-20304 (CVSS: 9.9) - Improper access control
  • CVE-2026-20310 (CVSS: 9.9) - Improper link resolution before file access
  • CVE-2026-20312 (CVSS: 8.8) - Cleartext storage of sensitive information
  • CVE-2026-20313 (CVSS: 7.7) - Improper validation of specified quantity in input

These Cisco SD-WAN IOS XE vulnerabilities affect Catalyst SD-WAN Software regardless of device configuration. The company has released fixed versions for each affected release track.

The Fixed Catalyst SD-WAN Versions

The Cisco SD-WAN IOS XE vulnerabilities have been addressed in the following versions:

  • 20.9: Fixed in 20.9.10
  • 20.10: Fixed in 20.12.8.1
  • 20.111: Fixed in 20.12.8.1
  • 20.12: Fixed in 20.12.8.1
  • 20.131: Fixed in 20.15.6
  • 20.141: Fixed in 20.15.6
  • 20.15: Fixed in 20.15.6
  • 20.161: Fixed in 20.18.4
  • 20.18: Fixed in 20.18.4
  • 26.1: Fixed in 26.1.2

Versions earlier than 20.9 require migration to a fixed release. Administrators should check their current version and plan the upgrade accordingly.

The IOS XE Vulnerabilities

Seven Cisco SD-WAN IOS XE vulnerabilities impact IOS XE Software. The flaws cover improper access control, command injection, and improper input validation.

The IOS XE flaws are:

  • CVE-2026-20267 (CVSS: 9.0) - Improper access control
  • CVE-2026-20268 (CVSS: 8.6) - Buffer overflow and out-of-bounds write
  • CVE-2026-20269 (CVSS: 8.6) - Improper control of a resource through its lifetime
  • CVE-2026-20270 (CVSS: 8.6) - Incorrect calculation covering integer overflow, underflow, and truncation
  • CVE-2026-20271 (CVSS: 8.6) - Insufficient control flow management covering infinite loops, uncontrolled recursion, and race conditions
  • CVE-2026-20272 (CVSS: 9.8) - Improper neutralization of special elements covering command, operating system, and argument injection
  • CVE-2026-20273 (CVSS: 8.6) - Improper input validation covering path traversals

CVE-2026-20272 carries the highest severity at 9.8. Command injection 
vulnerabilities of this severity are particularly dangerous because they allow attackers to execute arbitrary commands on the affected system.

The Fixed IOS XE Versions

The Cisco SD-WAN IOS XE vulnerabilities affecting IOS XE have been addressed in the following versions:

  • 17.9: Fixed in 17.9.10
  • 17.12: Fixed in 17.12.8
  • 17.15: Fixed in 17.15.6
  • 17.18: Fixed in 17.18.4 and 17.18.4a
  • 26.1: Fixed in 26.1.2

Administrators running any version prior to these fixed releases should update immediately.

The IMC CIMCown Vulnerability

Cisco also shipped fixes to address a high-severity security flaw in the web-based management interface of Integrated Management Controller. The vulnerability is tracked as CVE-2026-20200 and has been nicknamed CIMCown.

The Cisco SD-WAN IOS XE vulnerabilities are not the only flaws Cisco addressed. CVE-2026-20200 carries a CVSS score of 8.8. It is an improper validation of user-supplied input that could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system and elevate privileges to root.

Cisco acknowledged that a proof-of-concept exploit is available for CVE-2026-20200. This makes it a priority for organizations running IMC.

The company also addressed CVE-2026-20288, an improper validation of user-supplied input that could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands and elevate privileges to root.

The IMC Risk Assessment

Security researcher Christoph Peil, who discovered and reported CVE-2026-20200, provided a stark assessment of the risk. He said a compromise of the IMC means the controller sits in a position where it can influence the BIOS and SecureBoot and interact with the operating system above it.

"An attacker who gains root here can thereby nest themselves deeply and persistently in the system – far below what classic protective measures such as EDR solutions at the operating-system level can even see. The trust anchor of the entire server hardware is thus compromised."

This is a critical distinction. The Cisco SD-WAN IOS XE vulnerabilities affect network infrastructure. The IMC vulnerability affects the management controller that sits below the operating system. A successful exploit could give an attacker persistent access that traditional security tools cannot detect.

The Secure Firewall FMC Flaw

The Cisco SD-WAN IOS XE vulnerabilities disclosure comes less than a week after the company warned of active exploitation of CVE-2026-20316. That vulnerability affects Cisco Secure Firewall Management Center Software and could allow a low-privilege account to access sensitive data within susceptible systems.

CVE-2026-20316 carries a CVSS score of 5.3. The active exploitation makes it particularly concerning. Organizations running FMC should ensure they have applied the necessary updates.

The Role of AI in Security Testing

Cisco said the vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models. This is a notable development. AI is becoming an increasingly important tool for finding vulnerabilities before attackers do.

The usage of AI in security testing will definitely increase. The frontier of AI can help in analyzing the code and identifying vulnerabilities that may be unnoticed with other types of testing methods.

What Administrators Should Do

The Cisco SD-WAN IOS XE vulnerabilities require immediate attention. Administrators should:

  • Identify all Catalyst SD-WAN and IOS XE devices in their environment
  • Check current software versions against the fixed releases
  • Plan and schedule upgrades to the fixed versions
  • For IMC, apply the patches for CVE-2026-20200 and CVE-2026-20288
  • Review the Secure Firewall FMC advisory and apply patches if needed

The Cisco SD-WAN IOS XE vulnerabilities are not known to be actively exploited. However, the severity of the flaws, especially those with the CVSS 9.9 and 9.8 ratings, makes it necessary for them to be given priority.

Wrapping It Up

Cisco has released critical updates for multiple Cisco SD-WAN IOS XE vulnerabilities affecting Catalyst SD-WAN and IOS XE Software. The company also addressed the IMC CIMCown vulnerability with a proof-of-concept exploit available.

These patches come as a consequence of an internal security review that involved both conventional testing and AI models on the frontier. The vulnerabilities are not believed to be exploited actively at the moment, although their seriousness requires immediate measures.

Check your Cisco devices, apply the necessary updates, and ensure your network infrastructure is protected against these Cisco SD-WAN IOS XE vulnerabilities.

FAQ Section

What are the Cisco SD-WAN IOS XE vulnerabilities?

These are several critical security vulnerabilities in Cisco Catalyst SD-WAN Software and IOS XE Software. The vulnerabilities are improper input validation, improper access control, and command injection vulnerabilities, having CVSS scores up to 9.9.

Which versions are affected by the Cisco SD-WAN IOS XE vulnerabilities?

Catalyst SD-WAN versions 20.9 through 26.1 and IOS XE versions 17.9 through 17.18 and 26.1 are affected. Fixed versions are available for each release track.

What is the IMC CIMCown vulnerability?

CVE-2026-20200 is a high-severity flaw in Cisco's Integrated Management Controller web interface that allows authenticated attackers with low privileges to execute commands and elevate to root. A proof-of-concept exploit is available.

Has Cisco observed active exploitation of these vulnerabilities?

Cisco says the SD-WAN and IOS XE vulnerabilities are not known to be actively exploited. However, the IMC vulnerability has a public PoC exploit, and Cisco recently warned of active exploitation of a Secure Firewall FMC vulnerability.

What should administrators do?

Devices that are impacted should be identified, their versions verified, and any patches applied promptly. For IMC, CVE-2026-20200 and CVE-2026-20288 should be patched. The two vulnerabilities must be patched immediately.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067