Cisco has announced the release of patches for numerous vulnerabilities affecting its products, including critical issues in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). These updates, disclosed on Wednesday, aim to address security flaws that could potentially be exploited by attackers.
Critical Updates for Catalyst SD-WAN
The company has introduced five patches specifically for Catalyst SD-WAN, addressing several vulnerabilities categorized by their underlying causes. Three of these vulnerabilities, identified as CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, have been assigned a CVSS score of 9.9. These are described as issues with input validation, access control, and link resolution prior to file access.
The other two vulnerabilities, CVE-2026-20312 and CVE-2026-20313, are considered high-severity, focusing on the storage of sensitive information in plaintext and improper validation of input quantities.
IOS XE Vulnerabilities Addressed
Cisco’s IOS XE software also received attention, with seven new fixes released. These vulnerabilities, grouped by vulnerability class, include two critical issues: CVE-2026-20272 and CVE-2026-20267, carrying CVSS scores of 9.8 and 9.0, respectively. These involve command injection and access control flaws.
The remaining vulnerabilities in IOS XE have been marked as high-severity, addressing various security concerns that could be exploited if left unpatched.
FMC and Other Security Concerns
The Secure Firewall Management Center (FMC) has been patched for a particularly critical flaw, CVE-2026-20079, which has a perfect CVSS score of 10. This authentication bypass allows remote attackers to execute scripts and gain root access by sending crafted HTTP requests to vulnerable devices.
Additional patches have been released for high-severity issues in the Integrated Management Controller (IMC), IOS XE, and IOS, as well as medium-severity vulnerabilities in several other Cisco products.
Among these, CVE-2026-20200 in the IMC is notable for its potential to allow remote command execution with root privileges. Despite requiring authentication, proof-of-concept code exists that targets this flaw, affecting UCS C-Series M7 and M8 Rack Servers.
Cisco has stated that there is currently no evidence of these vulnerabilities being actively exploited. For further information, users are encouraged to consult Cisco’s security advisories page.
Related news includes recent vulnerabilities in other platforms, such as JetBrains TeamCity and Ruby on Rails, underscoring the importance of timely security updates.
