Cisco Releases Catalyst SD-WAN Software Security Hardening Guidance
The advisory addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments
Summary
The advisory addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments
Affected platforms
The following platforms are known to be affected:
Threat details
Additional Cisco advisories
Alongside the advisory included in this Cyber Alert, Cisco has released critical hardening guidance for Cisco IOS XE Software (covered in Cyber Alert CC-4824) and other important security advisories covered in a notification Cisco Advance Notification for Publication of August 5, 2026, Security Advisories.
Introduction
Cisco has published a security hardening guidance for Cisco Catalyst SD-WAN Software following a comprehensive internal security review. The update addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments. Cisco states that there is currently no evidence of active exploitation.
Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.
Successful exploitation of the affected vulnerability classes could allow an authenticated attacker to gain elevated privileges, bypass security controls, access sensitive information, manipulate files or system resources, or otherwise compromise the confidentiality, integrity, and availability of Cisco SD-WAN environments. Several vulnerability classes are associated with a maximum CVSS score of 9.9, indicating a potentially severe impact if exploited.
Vulnerability details
- CVE-2026-20303 - CWE-20 - Improper input validation (covers input validation, path traversal, and external path control) – Highest CVSS score: 9.9
- CVE-2026-20304 - CWE-284 - Improper access control (covers authorisation, authentication, privileges, and bypasses) – Highest CVSS Score: 9.9
- CVE-2026-20310 - CWE-59 - Improper link resolution before file access – Highest CVSS Score: 9.9
- CVE-2026-20312 - CWE-312 - Cleartext storage of sensitive information – Highest CVSS Score: 8.8
- CVE-2026-20313 - CWE-1284 - Improper validation of specified quantity in input – Highest CVSS Score: 7.7
Edge devices often targeted by attackers
Edge devices like Cisco Catalyst SD-WAN are often internet-facing by design and are highly attractive targets to attackers. An increasing number of edge device vulnerabilities disclosed each year are rapidly exploited by attackers. The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.
Organisations are strongly encouraged to follow NCSC-UK's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
Remediation advice
Affected organisations are urged to review Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026, assess exposure, and prioritise applying relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 6 August 2026 4:04 pm