Cisco has released an urgent security update addressing five vulnerabilities affecting Catalyst SD-WAN Software, several of which carry near-maximum CVSS severity scores.
The flaws were discovered as part of Cisco's internal security review and affect a broad range of Catalyst SD-WAN deployments. According to the advisory, there is currently no evidence that the vulnerabilities are being actively exploited in the wild, but the severity of several issues means organisations running affected releases should treat the updates as a priority.
What makes this advisory particularly important is that Cisco has confirmed there are no workarounds. For affected environments, upgrading to a fixed software release is the only available remediation.
Five Vulnerabilities Are Covered by the Advisory
The security update addresses five CVEs:
Their CVSS base scores range from 7.7 to 9.9, placing several firmly within the Critical severity category.
Three of the vulnerabilities reach a particularly serious 9.9 CVSS score.
The combination of input validation, access control and file-access weaknesses means this is not a single isolated software bug. Instead, Cisco is addressing several different security weaknesses across the Catalyst SD-WAN platform.
CVE-2026-20303 – Improper Input Validation
CVE-2026-20303 carries a CVSS score of 9.9 and relates to improper input validation.
The weakness includes issues such as path traversal and external control of file paths. In practical terms, improper handling of file paths can result in software accessing locations that were not originally intended by the application.
The advisory therefore treats this as one of the most serious vulnerabilities included in the update.
CVE-2026-20304 – Access Control and Authentication Weaknesses
Another 9.9-rated vulnerability, CVE-2026-20304, concerns improper access control.
Cisco's advisory groups several related weaknesses under this CVE, including problems involving authorization, authentication, privileges and access-control bypasses.
Access-control vulnerabilities are particularly significant in infrastructure platforms because those systems depend heavily on strict separation between authorised and unauthorised operations.
If those boundaries fail, the security model of the affected system can be undermined.
CVE-2026-20310 – Improper Link Resolution
CVE-2026-20310 also receives a 9.9 CVSS score.
This vulnerability involves improper link resolution before a file is accessed.
According to the advisory, the weakness could allow manipulation of symbolic links, potentially causing software to access unintended files.
Again, this is another file-system-related vulnerability, but its underlying mechanism differs from the path validation problem covered under CVE-2026-20303.
The fourth vulnerability, CVE-2026-20312, is rated 8.8.
It involves the cleartext storage of sensitive information.
If the underlying system were compromised, information such as credentials or other sensitive data stored without appropriate protection could potentially be exposed.
Although its CVSS rating is slightly lower than the three 9.9 vulnerabilities, an 8.8 score still places it firmly in the High severity range.
CVE-2026-20313 – Improper Quantity Validation
The final issue is CVE-2026-20313, which carries a CVSS rating of 7.7.
The vulnerability involves improper validation of a specified quantity supplied through input.
It is the lowest-rated vulnerability within this particular advisory, but Cisco still considers it significant enough to be addressed alongside the more severe issues.
Catalyst SD-WAN Is Affected Across Multiple Deployment Models
One of the more concerning aspects of the advisory is how broadly it applies.
Cisco states that the vulnerabilities affect Catalyst SD-WAN Software regardless of deployment model or device configuration.
That includes:
The advisory lists affected releases spanning older versions through the 20.x branch and also Release 26.1.
This means organisations cannot assume they are protected simply because they use a particular deployment configuration.
There Are No Configuration Workarounds
Perhaps the most important part of Cisco's guidance is that no workaround is available.
There is no configuration setting, feature toggle or deployment choice that removes exposure to these vulnerabilities.
Affected customers therefore need to move onto a fixed software release.
For IT teams, that significantly changes the remediation strategy.
When a workaround exists, administrators can sometimes temporarily reduce exposure while scheduling a more controlled maintenance window.
That option is not available here.
The actual software needs to be upgraded.
Which Catalyst SD-WAN Releases Need to Be Upgraded?
Cisco provides specific fixed releases depending on the currently installed Catalyst SD-WAN version.
| Current Catalyst SD-WAN Release | Required Fixed Release |
| Earlier than 20.9 | Migrate to a fixed release |
| 20.9 | 20.9.10 |
| 20.10 | 20.12.8.1 |
| 20.11 | 20.12.8.1 |
| 20.12 | 20.12.8.1 |
| 20.13 | 20.15.6 |
| 20.14 | 20.15.6 |
| 20.15 | 20.15.6 |
| 20.16 | 20.18.4 |
| 20.18 | 20.18.4 |
| 26.1 | 26.1 |
These are the fixed versions specified in the advisory and should be used when planning remediation.
For organisations running releases earlier than 20.9, Cisco does not provide a direct patch within that older branch. Those environments need to migrate to a supported fixed release instead.
Cisco-Managed Cloud Customers Are Already Covered
There is one important exception.
Customers using Cisco SD-WAN Cloud as a Cisco-managed service do not need to perform the upgrade themselves.
According to the advisory, Cisco has already deployed the fix on the backend using Release 20.15.602 for those managed environments.
That distinction matters because not every organisation using Catalyst SD-WAN necessarily controls the underlying software upgrade process.
For self-managed deployments, remediation remains the customer's responsibility.
For Cisco-managed cloud environments, Cisco has already applied the required backend update.
No Active Exploitation Has Been Observed So Far
There is at least one reassuring point in the advisory.
Cisco says it has not identified evidence that these vulnerabilities are currently being exploited in the wild.
That doesn't make the vulnerabilities less serious.
Three CVEs carry CVSS scores of 9.9, and Cisco has provided no workaround other than upgrading.
But the absence of known exploitation gives organisations an opportunity to patch before these weaknesses potentially become more widely targeted.
For security teams, this is exactly the sort of situation where acting before exploitation becomes commonplace is far preferable to reacting after an incident.
Why This Matters for Enterprise Networks
Catalyst SD-WAN environments can form an important part of an organisation's network infrastructure.
Based on the weaknesses listed in the advisory, the security concerns extend across several areas, including file handling, access control, authentication, privilege enforcement and sensitive data protection.
That combination is what makes the advisory more significant than a routine bug fix.
It isn't simply a cosmetic issue or minor stability problem.
Several fundamental security controls are involved.
Organisations running affected versions should therefore treat the upgrade as a security remediation exercise rather than an ordinary software maintenance update.
What IT Teams Should Do Now
The immediate priority is to identify whether any Catalyst SD-WAN components are running an affected release.
From there, IT and security teams should compare the installed version against Cisco's fixed-release matrix and plan the required upgrade.
Because Cisco has stated that there are no workarounds, organisations should not rely on configuration changes as a substitute for patching.
For environments with strict change-control requirements, that may mean coordinating maintenance windows quickly while still ensuring redundancy and business continuity are maintained during the upgrade process.
Customers using Cisco-managed SD-WAN Cloud should verify that their environment falls under the managed-service exception already patched by Cisco.
Final Thoughts
Cisco's latest Catalyst SD-WAN advisory deserves attention because of both the severity and breadth of the vulnerabilities involved.
Five CVEs are being addressed, with three reaching a near-maximum 9.9 CVSS score. The affected software spans multiple deployment models, and Cisco has made it clear that configuration changes cannot eliminate the risk.
The positive news is that Cisco has not reported active exploitation at this stage, and fixed releases are already available.
For organisations managing their own Catalyst SD-WAN infrastructure, however, the takeaway is straightforward: check the installed release, identify the appropriate fixed version and prioritise the upgrade.
With no workaround available, remaining on an affected release simply leaves unnecessary exposure in place.


Comments 0