Skip to content

Cisco patches critical Catalyst SD-WAN, IOS XE and Secure Firewall Management Center flaws

Share
Source: Badtech.org

SecurityWeek reported that Cisco released fixes for roughly two dozen vulnerabilities across its products, including critical issues in Catalyst SD-WAN, IOS XE and Secure Firewall Management Center.

For Catalyst SD-WAN, SecurityWeek and Secure ISS said Cisco identified CVE-2026-20303, CVE-2026-20304 and CVE-2026-20310 as critical vulnerabilities, and listed fixed releases 20.9.10, 20.12.8.1, 20.15.6, 20.18.4 and 26.1.2 by branch. The reporting also listed IOS XE fixes for CVE-2026-20272 and CVE-2026-20267, with fixed releases including 17.9.10, 17.12.8, 17.15.6, 17.18.4 or 17.18.4a, and 26.1.2.

SecurityWeek said Cisco also patched CVE-2026-20079 in Secure Firewall Management Center, described as a critical authentication-bypass flaw that could let a remote unauthenticated attacker execute scripts and commands and gain root privileges. The brief says no workarounds were available for the Catalyst SD-WAN and IOS XE hardening issues, and the reporting said Cisco was not aware of exploitation at disclosure time.

Sources