Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

🚨SEVERITY: CRITICAL — CVSS 9.9Security Advisory

TL;DR 📌

  • As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To…
  • Highest CVSS: 9.9 (Critical).
  • Fix available — see the first fixed release below.
  • CVEs: CVE-2026-20303, CVE-2026-20304, CVE-2026-20310.

What it is

As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class ��� Common Weakness Enumeration (CWE) ��� and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

Fixed releases

Affected release First fixed release
20.9 20.9.10
20.10 20.12.8.1
20.111 20.12.8.1
20.12 20.12.8.1
20.131 20.15.6
20.141 20.15.6
20.15 20.15.6
20.161 20.18.4
20.18 20.18.4
26.1 26.1.2

For leadership 🧭

Executive summary. Cisco has issued hardening updates for Catalyst SD-WAN Manager and Controller after its own engineers found five vulnerabilities during internal review, the worst of which scores 9.9 and requires only low privileges and no user interaction to fully compromise confidentiality, integrity and availability. These were not found through active attacks, but given the severity and central role these systems play in managing SD-WAN fabric, patching should be scheduled as a priority rather than routine maintenance.

Why it matters:

  • SD-WAN Manager and Controller sit at the centre of the WAN fabric, controlling routing policy and device configuration across every connected site, so compromise here has fleet-wide reach.
  • The top-scoring flaw (9.9) needs only low privileges over the network and no user interaction, meaning an attacker with limited access could still achieve full control over confidentiality, integrity and availability.
  • Cisco states there are no workarounds, so the only way to close these five CWE-grouped vulnerabilities is to install the fixed software builds.
  • The vulnerabilities were found during Cisco’s own internal testing rather than reported by outsiders, so there is no public proof-of-concept detail to gauge how straightforward exploitation would be in practice.

Now / Next / Later:

  • Now: Identify every Catalyst SD-WAN Manager and Controller instance in your estate and check its running software version against Cisco’s affected-release table.
  • Next: Schedule an upgrade to the first fixed release for your train (e.g. 20.9.10, 20.12.8.1, 20.15.6, 20.18.4 or 26.1.2) in the next available change window, since no workaround exists.
  • Later: Bring SD-WAN control-plane components into your regular patch cadence and restrict administrative access to these management systems to trusted, monitored networks only.

Source