Cisco has released security updates for roughly two dozen vulnerabilities across Catalyst SD-WAN, IOS XE, IOS Software, Secure Firewall Management Center (FMC), and Integrated Management Controller (IMC), including several critical and high-severity flaws. The most severe issue, CVE-2026-20079 in FMC, carries a CVSS 10.0 rating and could allow a remote unauthenticated attacker to send crafted HTTP requests, execute scripts, and obtain root privileges. Cisco also patched critical weaknesses in SD-WAN and IOS XE, while a notable IMC flaw, CVE-2026-20200, affects UCS C-Series M7 and M8 Rack Servers in standalone mode and has publicly available proof-of-concept code.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A CSIRT Italia notice highlighted CVE-2026-20316, a static-credential vulnerability in Cisco Secure Firewall Management Center's web interface, as being actively exploited in the wild. The flaw allows an unauthenticated remote attacker to log in with a low-privilege account using static credentials and access sensitive data stored on the device.
Cisco stated that it was not aware of any of the patched vulnerabilities being exploited in the wild at the time of disclosure.
Cisco highlighted CVE-2026-20200 in Integrated Management Controller as a high-severity vulnerability that can allow authenticated remote command execution and root privilege gain on affected UCS C-Series M7 and M8 Rack Servers in standalone mode. Cisco also warned that proof-of-concept code exists for this flaw.
Cisco identified fixed release trains for affected products, including Catalyst SD-WAN versions 26.1.2, 20.18.4, 20.15.6, 20.12.8.1, and 20.9.10; IOS XE versions 26.1.2, 17.18.4, 17.15.6, 17.12.8, and 17.9.10; and IMC versions 6.0(2.260044) and 4.3(6.260033). For some issues, Cisco directed customers to use Cisco Software Checker to determine affected and remediated releases.
Cisco released patches and security updates for roughly two dozen vulnerabilities affecting Catalyst SD-WAN, IOS XE, IOS, Secure Firewall Management Center, and Integrated Management Controller. The updates included fixes for critical flaws such as FMC CVE-2026-20079, Catalyst SD-WAN CVE-2026-20303/CVE-2026-20304/CVE-2026-20310, IOS XE CVE-2026-20267/CVE-2026-20272, and IMC CVE-2026-20200.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourcesecurityweek.com
Open sourceboho.or.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.