Cisco released security hardening updates for Catalyst SD-WAN after an internal security review uncovered multiple remotely exploitable vulnerabilities affecting Catalyst SD-WAN Controller and Catalyst SD-WAN Manager across a wide range of software versions. The most severe issues include CVE-2026-20303 and CVE-2026-20304, both rated CVSS 9.9, covering improper input validation and improper access control, as well as CVE-2026-20310, a critical improper link resolution flaw (CWE-59) rated CVSS 9.1. Cisco also disclosed CVE-2026-20312, an information disclosure issue tied to cleartext storage of sensitive information (CWE-312) with a CVSS 8.8 score.
Cisco said the vulnerabilities were discovered internally, including with assistance from frontier AI models, and that it has no evidence of active exploitation. The company said there are no workarounds, making upgrades to fixed or hardened releases the required remediation path; customers on unsupported versions may need to migrate before applying fixes. Cisco-managed SD-WAN Cloud customers do not need to take action because backend fixes were already applied in Release 20.15.602, while other organizations are being directed to update to the latest Catalyst SD-WAN software and review Cisco's advisory for affected-version details.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Cisco published CVE-2026-20312 for multiple Catalyst SD-WAN information disclosure vulnerabilities involving cleartext storage of sensitive information, rated high with a CVSS score of 8.8. The record says the issues were found during Cisco's internal review and addressed in hardening releases.
Cisco published CVE-2026-20310 for an improper link resolution before file access vulnerability in Catalyst SD-WAN, rated critical with a CVSS score of 9.1. The record says it was discovered internally and remediated through Cisco's security hardening releases.
Cisco published CVE-2026-20304 for improper access control vulnerabilities in Catalyst SD-WAN, rated critical with a CVSS score of 9.9. The record states the issue is remotely exploitable and covered by the same SD-WAN hardening advisory.
Cisco published CVE-2026-20303 for multiple Catalyst SD-WAN improper input validation vulnerabilities, rated critical with a CVSS score of 9.9. The advisory ties the issue to Cisco's SD-WAN hardening release and affected Controller and Manager versions across many branches.
A subsequent report said Cisco disclosed multiple Catalyst SD-WAN vulnerabilities affecting all deployment models, stated there was no evidence of active exploitation, and said there were no workarounds. Cisco listed fixed releases by branch and said unsupported releases earlier than 20.9 must be migrated to supported versions.
Cisco said customers using Cisco-managed SD-WAN Cloud do not need to take action because the fix was already applied on the backend. The company identified Release 20.15.602 as the backend release containing that remediation.
Cisco said the internal review resulted in software hardening releases to address multiple internally discovered Catalyst SD-WAN vulnerabilities. The fixes were made available as security hardening updates, with upgrades required because no workarounds exist.
Cisco said its Catalyst SD-WAN engineering team identified multiple vulnerabilities during a comprehensive internal security review. A later report added that Cisco used traditional internal testing processes together with frontier AI models to uncover the issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.