Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

🚨SEVERITY: CRITICAL — CVSS 9.9Security Advisory

TL;DR 📌

  • As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To…
  • Highest CVSS: 9.9 (Critical).
  • Fix available — see the first fixed release below.
  • CVEs: CVE-2026-20303, CVE-2026-20304, CVE-2026-20310.

What it is

As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class ��� Common Weakness Enumeration (CWE) ��� and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

Fixed releases

Affected release First fixed release
20.9 20.9.10
20.10 20.12.8.1
20.111 20.12.8.1
20.12 20.12.8.1
20.131 20.15.6
20.141 20.15.6
20.15 20.15.6
20.161 20.18.4
20.18 20.18.4
26.1 26.1.2

For leadership 🧭

Executive summary. Risk is Critical (CVSS 9.9) across any Cisco kit you run. Vendor fixes are available; prioritise upgrade within 48-72 hours.

Why it matters:

  • Exposure depends on deployment topology and which access paths reach the affected component.
  • Treat internet-facing and management-plane instances as higher risk than internal-only ones.
  • Keep monitoring for abnormal authentication and configuration events until upgrades complete.

Now / Next / Later:

  • Now: confirm whether you run the affected versions, and check exposure of any that are internet-facing.
  • Next: upgrade to the first fixed release in the table above, through an approved change window.
  • Later: add a control check so builds cannot drift back onto a vulnerable train.

Source