Cisco Patches 12 Critical SD-WAN and IOS XE Flaws, Three Rated 9.8+ CVSS
Cisco has released security updates addressing 12 vulnerabilities across its Catalyst SD-WAN and IOS XE Software platforms, three of which carry a CVSS score of 9.8 or higher. The flaws were uncovered during an internal security review that combined Cisco's standard testing processes with frontier AI models, marking one of the first major coordinated disclosures where generative AI tooling played a direct role in vulnerability discovery. While Cisco confirmed none of the issues are known to be under active exploitation, the severity ratings warrant urgent attention from network administrators running affected devices in either autonomous or controller mode.
The five SD-WAN vulnerabilities include CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each scoring a critical 9.9 and stemming from improper input validation, broken access control, and a path-traversal flaw tied to insecure link resolution before file access. Additional issues include CVE-2026-20312 (CVSS 8.8), a cleartext storage vulnerability exposing sensitive information, and CVE-2026-20313 (CVSS 7.7), which involves improper validation of input quantities. Fixed builds span Cisco SD-WAN versions 20.9 through 26.1, with branches like 20.12 resolving in 20.12.8.1 and 20.15 resolving in 20.15.6. Organizations managing distributed network edge infrastructure should verify their firmware and use a port scanner to confirm exposure of management interfaces to untrusted networks.
The seven IOS XE flaws are equally severe, headlined by CVE-2026-20272 with a CVSS score of 9.8 — an improper neutralization vulnerability enabling command, operating system, and argument injection. CVE-2026-20267 follows at 9.0 due to an access control failure, while CVE-2026-20268 through CVE-2026-20271 and CVE-2026-20273 all carry an 8.6 rating, covering buffer overflows, out-of-bounds writes, resource lifecycle mismanagement, incorrect numeric calculations, insufficient control flow handling, and input validation errors. Patches ship across IOS XE versions 17.9, 17.12, 17.15, 17.18, and 26.1, with fixes landing in releases like 17.12.8 and 17.18.4a. Given the web-based management interface implications, administrators should run an SSL/TLS checker against their management endpoints to confirm certificates and cipher configurations remain hardened.
Beyond patching, defenders should audit credential hygiene on privileged accounts, since several of the addressed access control flaws could have allowed unauthorized administrative actions. Running a password checker against active credentials used on Cisco management planes is a quick win while remediation proceeds. Cisco customers are advised to review the official security advisories, identify device inventory against the affected version matrix, and apply updates without delay to eliminate the risk of pre-authenticated remote compromise.