
CISCO has issued patches for two dozen security flaws affecting its Catalyst SD‑WAN, IOS XE and Secure Firewall Management Center products (SecurityWeek reports). The updates address several critical bugs, including CVE‑2026‑20079, CVE‑2026‑20303 and CVE‑2026‑20310, which could allow remote attackers to execute code or bypass security controls.
The most severe flaw, tracked as CVE‑2026‑20079, affects the Secure Firewall Management Center and carries a CVSS score of 10, permitting an unauthenticated attacker to run arbitrary commands on the device (Cisco advisory). Two high‑impact issues in the Catalyst SD‑WAN platform, CVE‑2026‑20303 (CVSS 9.9) and CVE‑2026‑20310 (CVSS 9.1), arise from insufficient validation of user‑supplied input, which could enable bypass of security checks or remote code execution (SecurityOnline notes).
In addition, Cisco resolved multiple command injection vulnerabilities in IOS XE that could let an attacker execute arbitrary code with elevated privileges, and several flaws in the Integrated Management Controller that could be abused to bypass authentication (advisory). The vendor rates a number of these issues as high or medium severity, and stresses that upgrading to the specified fixed versions is the only reliable remediation.
So far, Cisco has not observed any active exploitation of these vulnerabilities in the wild, and no threat‑actor groups have been linked to the flaws (advisory). The bugs were discovered during internal testing and reported through coordinated disclosure, highlighting the value of proactive code review in network‑edge gear.
Because Catalyst SD‑WAN and Secure Firewall Management Center are commonly deployed at the edge of enterprise networks, a compromise could let an intruder intercept traffic, alter security policies or move laterally to other systems. Applying the updates quickly limits the chance that attackers chain these bugs with other weaknesses to achieve a deeper breach.
Administrators should consult the release notes linked in Cisco’s advisory and upgrade affected devices to the fixed versions as soon as possible (SecurityWeek). After updating, they should verify the patch level via the command‑line interface or management console and review any altered configurations that might have been introduced during the upgrade process.
In parallel, security teams are advised to inspect authentication and command‑execution logs for any signs of unexpected activity, enforce multi‑factor authentication on management interfaces, and segment management traffic from user‑filled subnets to reduce the attack surface. Staying current with Cisco’s security notices will help catch similar issues early.