Skip to main content

Cisco Releases Catalyst SD-WAN Software Security Hardening Guidance

The advisory addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The advisory addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments


Threat details

Additional Cisco advisories

Alongside the advisory included in this Cyber Alert, Cisco has released critical hardening guidance for Cisco IOS XE Software (covered in Cyber Alert CC-4824) and other important security advisories covered in a notification Cisco Advance Notification for Publication of August 5, 2026, Security Advisories.


Introduction

Cisco has published a security hardening guidance for Cisco Catalyst SD-WAN Software following a comprehensive internal security review. The update addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments. Cisco states that there is currently no evidence of active exploitation.

Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Successful exploitation of the affected vulnerability classes could allow an authenticated attacker to gain elevated privileges, bypass security controls, access sensitive information, manipulate files or system resources, or otherwise compromise the confidentiality, integrity, and availability of Cisco SD-WAN environments. Several vulnerability classes are associated with a maximum CVSS score of 9.9, indicating a potentially severe impact if exploited.


Vulnerability details

  • CVE-2026-20303 - CWE-20 - Improper input validation (covers input validation, path traversal, and external path control) – Highest CVSS score: 9.9
  • CVE-2026-20304 - CWE-284 - Improper access control (covers authorisation, authentication, privileges, and bypasses) – Highest CVSS Score: 9.9
  • CVE-2026-20310 - CWE-59 - Improper link resolution before file access  – Highest CVSS Score: 9.9
  • CVE-2026-20312 - CWE-312 - Cleartext storage of sensitive information  – Highest CVSS Score: 8.8
  • CVE-2026-20313 - CWE-1284  - Improper validation of specified quantity in input  – Highest CVSS Score: 7.7

Edge devices often targeted by attackers

Edge devices like Cisco Catalyst SD-WAN are often internet-facing by design and are highly attractive targets to attackers. An increasing number of edge device vulnerabilities disclosed each year are rapidly exploited by attackers. The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.

Organisations are strongly encouraged to follow NCSC-UK's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.


Remediation advice

Affected organisations are urged to review Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026assess exposure, and prioritise applying relevant updates.



CVE Vulnerabilities

Last edited: 6 August 2026 4:04 pm