T

Threats

Cisco Releases Critical Security Hardening Updates

Cisco published security hardening releases on 5 August 2026 for internally discovered vulnerabilities in Cisco IOS XE Software and Cisco Catalyst SD-WAN Software. The issues covered here are not known to be actively exploited, but their maximum potential severity is critical.

Cisco has provided fixed software and states that no workarounds address these vulnerabilities. Organisations should identify exposed releases and prioritise upgrades.


Overview


Affected Versions

Cisco IOS XE Software

These vulnerabilities affect Cisco IOS XE Software in autonomous or controller mode, regardless of device configuration.

  • Affected: Release 17.9 before 17.9.10; 17.12 before 17.12.8; 17.15 before 17.15.6; 17.18 before 17.18.4 or 17.18.4a; and 26.1 before 26.1.2.

  • Fixed: 17.9.10, 17.12.8, 17.15.6, 17.18.4, 17.18.4a and 26.1.2.

  • Not affected: Only products listed by Cisco as vulnerable are known to be affected. Cisco Catalyst 3650 and 3850 Series Switches do not run the evaluated releases and were not evaluated, so they should not be treated as confirmed unaffected by this review.

  • Source: Cisco IOS XE Software Security Hardening Release: August 2026

Cisco Catalyst SD-WAN Software

These vulnerabilities affect Cisco Catalyst SD-WAN Software regardless of configuration across on-premises, Cloud-Pro, Cisco Managed Cloud and government deployment types.

  • Affected: Releases earlier than 20.9; 20.9 before 20.9.10; 20.10, 20.11 and 20.12 before 20.12.8.1; 20.13, 20.14 and 20.15 before 20.15.6; 20.16 and 20.18 before 20.18.4; and 26.1 before 26.1.2.

  • Fixed: 20.9.10, 20.12.8.1, 20.15.6, 20.18.4 and 26.1.2. Cisco SD-WAN Cloud (Cisco Managed) is also fixed in cloud release 20.15.602, with no customer action required for that service.

  • Not affected: Only products listed by Cisco as vulnerable are known to be affected.

  • Source: Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026


Vulnerability Breakdown

CVE-2026-20303 - Improper Input Validation

  • Severity: Critical

  • CVSS: 9.9

  • Description: Cisco groups internally discovered improper input validation weaknesses under this CVE. The class includes input validation, path traversal and external path control issues.

  • Impact: The most impactful underlying issue may compromise confidentiality, integrity and availability across a security boundary.

  • Conditions: The advisory's highest-severity vector for this grouping requires network access and low privileges, with no user interaction.

  • Affected product: Cisco Catalyst SD-WAN Software.

  • Source: Cisco Catalyst SD-WAN Security Hardening Advisory

CVE-2026-20304 - Improper Access Control

  • Severity: Critical

  • CVSS: 9.9

  • Description: Cisco groups internally discovered authorisation, authentication, privilege and bypass weaknesses under this CVE.

  • Impact: The most impactful underlying issue may permit unauthorised actions and compromise confidentiality, integrity and availability across a security boundary.

  • Conditions: The advisory's highest-severity vector requires network access and low privileges, with no user interaction.

  • Affected product: Cisco Catalyst SD-WAN Software.

  • Source: Cisco Catalyst SD-WAN Security Hardening Advisory

CVE-2026-20310 - Improper Link Resolution Before File Access

  • Severity: Critical

  • CVSS: 9.9

  • Description: Cisco groups internally discovered weaknesses involving improper link resolution before file access under this CVE.

  • Impact: The most impactful underlying issue may enable unintended file access and compromise confidentiality, integrity and availability across a security boundary.

  • Conditions: The advisory's highest-severity vector requires network access and low privileges, with no user interaction.

  • Affected product: Cisco Catalyst SD-WAN Software.

  • Source: Cisco Catalyst SD-WAN Security Hardening Advisory

CVE-2026-20272 - Improper Neutralisation of Special Elements

  • Severity: Critical

  • CVSS: 9.8

  • Description: Cisco groups internally discovered command, operating system and argument injection weaknesses under this CVE.

  • Impact: The most impactful underlying issue may compromise confidentiality, integrity and availability.

  • Conditions: The advisory's critical vector requires network access, no privileges and no user interaction.

  • Affected product: Cisco IOS XE Software.

  • Source: Cisco IOS XE Security Hardening Advisory

CVE-2026-20267 - Improper Access Control

  • Severity: Critical

  • CVSS: 9.0

  • Description: Cisco groups internally discovered authorisation, authentication, privilege and bypass weaknesses under this CVE.

  • Impact: The most impactful underlying issue may permit unauthorised access or actions. Cisco does not publish bug-level impact details for the grouped weaknesses.

  • Conditions: Cisco does not publish issue-specific prerequisites for the grouped weaknesses in this CVE.

  • Affected product: Cisco IOS XE Software.

  • Source: Cisco IOS XE Security Hardening Advisory


Mitigation

  • Upgrade each affected Cisco IOS XE or Cisco Catalyst SD-WAN deployment to the appropriate fixed release listed above.

  • Migrate Cisco Catalyst SD-WAN releases earlier than 20.9 to a fixed, supported release.

  • Move end-of-maintenance Cisco Catalyst SD-WAN releases 20.11, 20.13, 20.14 and 20.16 to a supported release.

  • Confirm hardware capacity and configuration compatibility before upgrading.

  • Contact Cisco TAC or the organisation's contracted maintenance provider if the correct upgrade path is unclear.

There are no workarounds. Risk reduction controls should not be treated as substitutes for the fixed software.


Summary for IT Teams

  • Products: Cisco IOS XE Software and Cisco Catalyst SD-WAN Software

  • Threat Level: Critical, CVSS up to 9.9

  • Action Required: Identify affected releases and upgrade to Cisco's first fixed release or a later supported release. Prioritise internet-reachable and privileged management environments.


Reference


Need Help?

Secure ISS can help your organisation assess Cisco IOS XE and Catalyst SD-WAN exposure, plan a supported upgrade path and validate remediation.

Please call 1300 769 460 or contact the Secure ISS team for assistance.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.