cisco just patched three near-perfect 9.9 bugs in the box that runs your whole network

Three flaws in Catalyst SD-WAN and IOS XE score 9.9 out of 10 — and one of them lets an attacker reach files no matter how the device is configured.

Aliteq
Ravi Malhotra · Hardware Editor

What you need to know

Cisco patched 12 flaws across Catalyst SD-WAN and IOS XE on August 5, 2026, three scoring CVSS 9.9: CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310.

What you need to know

The three 9.9 bugs affect Catalyst SD-WAN regardless of how the device is configured — there's no safe setup that avoids exposure.

What you need to know

A separate 9.8 command-injection bug (CVE-2026-20272) hits IOS XE running in autonomous or controller mode.

What you need to know

None of the twelve are known to be actively exploited yet, but a proof-of-concept already exists for a related Cisco IMC bug, CVE-2026-20200.

What you need to know

Fixed versions: IOS XE 17.9.10 / 17.12.8 / 17.15.6 / 17.18.4 (or 4a) / 26.1.2; Catalyst SD-WAN 20.9.10 / 20.12.8.1 / 20.15.6 / 20.18.4 / 26.1.2. There are no workarounds — you have to upgrade.

No workaround exists

Cisco is explicit about this one: there is no mitigation short of installing the fixed software. Disabling a feature or restricting an interface doesn't help, because the SD-WAN flaws apply…

Aliteq

Read the full story

cisco just patched three near-perfect 9.9 bugs in the box that runs your whole network

Read the full story on Aliteq