CISCO has patched five critical vulnerabilities in the Catalyst SD-WAN software, with two vulnerabilities scoring CVSS 9.9. Cisco reports no active exploitation of these flaws yet. The vulnerabilities include issues related to improper input validation and access control that could allow bypassing of security checks. Each flaw affects various deployment types, including cloud and on-prem setups. Users are urged to upgrade to specific fixed releases as there are no workarounds.
CVE-2026-20303 & CVE-2026-20304: Cisco SD-WAN Flaws Hit CVSS 9.9
CyberSIXT Evidence Panel
Primary Source
sec.cloudapps.cisco.com
Article by CyberSIXT