T
Threats
Cisco Releases Critical Security Hardening Updates
Cisco published security hardening releases on 5 August 2026 for internally discovered vulnerabilities in Cisco IOS XE Software and Cisco Catalyst SD-WAN Software. The issues covered here are not known to be actively exploited, but their maximum potential severity is critical.
Cisco has provided fixed software and states that no workarounds address these vulnerabilities. Organisations should identify exposed releases and prioritise upgrades.
Overview
CVE IDs: CVE-2026-20267, CVE-2026-20272, CVE-2026-20303, CVE-2026-20304, CVE-2026-20310
Overall severity: Critical
Highest CVSS score: 9.9
Publication date: 5 August 2026
Exploitation status: Cisco PSIRT is not aware of public announcements or malicious use
Workarounds: None available
Affected Versions
Cisco IOS XE Software
These vulnerabilities affect Cisco IOS XE Software in autonomous or controller mode, regardless of device configuration.
Affected: Release 17.9 before 17.9.10; 17.12 before 17.12.8; 17.15 before 17.15.6; 17.18 before 17.18.4 or 17.18.4a; and 26.1 before 26.1.2.
Fixed: 17.9.10, 17.12.8, 17.15.6, 17.18.4, 17.18.4a and 26.1.2.
Not affected: Only products listed by Cisco as vulnerable are known to be affected. Cisco Catalyst 3650 and 3850 Series Switches do not run the evaluated releases and were not evaluated, so they should not be treated as confirmed unaffected by this review.
Source: Cisco IOS XE Software Security Hardening Release: August 2026
Cisco Catalyst SD-WAN Software
These vulnerabilities affect Cisco Catalyst SD-WAN Software regardless of configuration across on-premises, Cloud-Pro, Cisco Managed Cloud and government deployment types.
Affected: Releases earlier than 20.9; 20.9 before 20.9.10; 20.10, 20.11 and 20.12 before 20.12.8.1; 20.13, 20.14 and 20.15 before 20.15.6; 20.16 and 20.18 before 20.18.4; and 26.1 before 26.1.2.
Fixed: 20.9.10, 20.12.8.1, 20.15.6, 20.18.4 and 26.1.2. Cisco SD-WAN Cloud (Cisco Managed) is also fixed in cloud release 20.15.602, with no customer action required for that service.
Not affected: Only products listed by Cisco as vulnerable are known to be affected.
Source: Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
Vulnerability Breakdown
CVE-2026-20303 - Improper Input Validation
Severity: Critical
CVSS: 9.9
Description: Cisco groups internally discovered improper input validation weaknesses under this CVE. The class includes input validation, path traversal and external path control issues.
Impact: The most impactful underlying issue may compromise confidentiality, integrity and availability across a security boundary.
Conditions: The advisory's highest-severity vector for this grouping requires network access and low privileges, with no user interaction.
Affected product: Cisco Catalyst SD-WAN Software.
CVE-2026-20304 - Improper Access Control
Severity: Critical
CVSS: 9.9
Description: Cisco groups internally discovered authorisation, authentication, privilege and bypass weaknesses under this CVE.
Impact: The most impactful underlying issue may permit unauthorised actions and compromise confidentiality, integrity and availability across a security boundary.
Conditions: The advisory's highest-severity vector requires network access and low privileges, with no user interaction.
Affected product: Cisco Catalyst SD-WAN Software.
CVE-2026-20310 - Improper Link Resolution Before File Access
Severity: Critical
CVSS: 9.9
Description: Cisco groups internally discovered weaknesses involving improper link resolution before file access under this CVE.
Impact: The most impactful underlying issue may enable unintended file access and compromise confidentiality, integrity and availability across a security boundary.
Conditions: The advisory's highest-severity vector requires network access and low privileges, with no user interaction.
Affected product: Cisco Catalyst SD-WAN Software.
CVE-2026-20272 - Improper Neutralisation of Special Elements
Severity: Critical
CVSS: 9.8
Description: Cisco groups internally discovered command, operating system and argument injection weaknesses under this CVE.
Impact: The most impactful underlying issue may compromise confidentiality, integrity and availability.
Conditions: The advisory's critical vector requires network access, no privileges and no user interaction.
Affected product: Cisco IOS XE Software.
CVE-2026-20267 - Improper Access Control
Severity: Critical
CVSS: 9.0
Description: Cisco groups internally discovered authorisation, authentication, privilege and bypass weaknesses under this CVE.
Impact: The most impactful underlying issue may permit unauthorised access or actions. Cisco does not publish bug-level impact details for the grouped weaknesses.
Conditions: Cisco does not publish issue-specific prerequisites for the grouped weaknesses in this CVE.
Affected product: Cisco IOS XE Software.
Mitigation
Upgrade each affected Cisco IOS XE or Cisco Catalyst SD-WAN deployment to the appropriate fixed release listed above.
Migrate Cisco Catalyst SD-WAN releases earlier than 20.9 to a fixed, supported release.
Move end-of-maintenance Cisco Catalyst SD-WAN releases 20.11, 20.13, 20.14 and 20.16 to a supported release.
Confirm hardware capacity and configuration compatibility before upgrading.
Contact Cisco TAC or the organisation's contracted maintenance provider if the correct upgrade path is unclear.
There are no workarounds. Risk reduction controls should not be treated as substitutes for the fixed software.
Summary for IT Teams
Products: Cisco IOS XE Software and Cisco Catalyst SD-WAN Software
Threat Level: Critical, CVSS up to 9.9
Action Required: Identify affected releases and upgrade to Cisco's first fixed release or a later supported release. Prioritise internet-reachable and privileged management environments.
Reference
Cisco IOS XE Software Security Hardening Release: August 2026
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
Need Help?
Secure ISS can help your organisation assess Cisco IOS XE and Catalyst SD-WAN exposure, plan a supported upgrade path and validate remediation.
Please call 1300 769 460 or contact the Secure ISS team for assistance.

