/00 — boot sequence

Hello.

Article

Cisco IOS XE Vulnerabilities: 12 Flaws Patched, 9.9 CVSS

August 9, 2026•7 min read
cisco ios-xe sd-wan vulnerability security networking

The Cisco IOS XE vulnerabilities patched this week should be on every network team's radar. On August 5, 2026, Cisco shipped two hardening releases that fix 12 vulnerabilities in IOS XE and Catalyst SD-WAN software, including three CVEs with a CVSS score of 9.9 and a command injection grouping rated 9.8. The same advisory batch also patched a severity 10.0 authentication bypass in Cisco Secure Firewall Management Center (FMC) and an Integrated Management Controller flaw with a public proof-of-concept. Cisco says the issues came from an internal security review that used its existing testing processes plus frontier AI models, and reports no active exploitation so far.

What happened

Cisco publishes security advisories when it fixes product flaws. On August 5 it released two "security hardening" advisories, one for Catalyst SD-WAN and one for Cisco IOS XE. Instead of one advisory per bug, Cisco grouped the issues by underlying weakness class (Common Weakness Enumeration, or CWE) and assigned one CVE per group. That is why five CVEs cover many individual defects in SD-WAN and seven cover similar classes in IOS XE.

Both advisories say the defects were found internally, using Cisco's existing testing processes and frontier AI models. PSIRT reports no public disclosure or malicious use of these issues so far.

Vulnerability details: the Catalyst SD-WAN CVEs

Catalyst SD-WAN software is the control plane for Cisco's SD-WAN deployments, which span on-premises controllers, cloud-hosted managers, and FedRAMP environments. Five CVE groups were assigned there:

CVE IDCVSSWeakness classWhat it covers
CVE-2026-203039.9CWE-20Improper input validation, path traversal, external path control
CVE-2026-203049.9CWE-284Improper access control, auth bypass, privilege issues
CVE-2026-203109.9CWE-59Improper link resolution before file access
CVE-2026-203128.8CWE-312Cleartext storage of sensitive information
CVE-2026-203137.7CWE-1284Improper validation of specified quantity in input

The 9.9 score reflects remote exploitation with low privileges, a scope change into the underlying system, and full compromise of confidentiality, integrity, and availability. Several groupings cover classic web application mistakes (path traversal, link following) that are straightforward to chain into file read or write primitives on a management appliance.

Vulnerability details: the IOS XE CVEs

IOS XE runs on the most common Cisco enterprise routers and switches, in both autonomous mode and controller mode. Seven CVE groups were assigned:

CVE IDCVSSWeakness classRoot cause
CVE-2026-202729.8CWE-74Improper neutralization of special elements; command, OS, and argument injection
CVE-2026-202679.0CWE-284Improper access control
CVE-2026-202688.6CWE-119Buffer overflow, out of bounds write
CVE-2026-202698.6CWE-664Improper resource lifetime control, null dereference, invalid frees
CVE-2026-202708.6CWE-682Incorrect calculation, integer overflow, truncation
CVE-2026-202718.6CWE-691Insufficient control flow management, infinite loops, race conditions
CVE-2026-202738.6CWE-20Improper input validation, path traversal

The 9.8 rating for CVE-2026-20272 is the standout: a command injection reachable without authentication on the device, the kind a remote attacker can turn into a foothold in the network fabric. CVE-2026-20267 (9.0) covers access control weaknesses with high impact but high attack complexity.

The rest of the batch

Cisco's August 5 advisory cycle also covered roughly a dozen more alerts across other product lines. The two worth reading first:

  • CVE-2026-20079 in Cisco Secure Firewall Management Center, the management platform for the Firewall family, is a severity 10.0 authentication bypass. An unauthenticated, remote attacker can send crafted HTTP requests and run script files as root, per Cisco.
  • CVE-2026-20200 in Cisco Integrated Management Controller (IMC), used by UCS C-Series rack servers, is an argument injection in the web interface. Low privileged credentials are enough, and it gives arbitrary command execution as root. A public proof-of-concept named CIMCown was published by researcher Christoph Peil of NSIDE ATTACK LOGIC.

Beyond those two, the batch included high-severity fixes in IOS and more IMC issues, plus medium-severity fixes for IOS XE, Terminal Services Agent, Catalyst SD-WAN Manager, RoomOS, and IMC.

Affected systems

  • Catalyst SD-WAN: all deployments are affected regardless of configuration. On-premise, SD-WAN Cloud-Pro, SD-WAN Cloud (Cisco managed), and SD-WAN for Government (FedRAMP) are all in scope.
  • IOS XE: all affected when running in autonomous or controller mode. The review covered releases 17.9, 17.12, 17.15, 17.18, and 26.1. Cisco Catalyst 3650 and 3850 Series Switches were not evaluated because they do not run these releases.

Mitigation and patching

Cisco provides no workarounds for any device in these CVEs. Upgrading to a fixed release is the only full remediation. The fixed release tables from the advisories:

IOS XE releases: 17.9 to 17.9.10, 17.12 to 17.12.8, 17.15 to 17.15.6, 17.18 to 17.18.4 or 17.18.4a, and 26.1 to 26.1.2. Catalyst SD-WAN releases: versions before 20.9 migrate to a fixed release, 20.9 to 20.9.10, 20.10, 20.11 and 20.12 to 20.12.8.1, 20.13, 20.14 and 20.15 to 20.15.6, 20.16 and 20.18 to 20.18.4, and 26.1 to 26.1.2. The Cisco-managed SD-WAN Cloud service was updated to 20.15.602 with no user action needed.

Start the upgrade plan now. These devices sit on the network edge and in the data center, and there is no temporary hardening that buys time.

Detection

Cisco provides no detection signatures for these flaws. The practical stance while you plan upgrades: watch management-plane access logs for unusual patterns, unexpected configuration changes, or new local accounts, and watch for public PoCs, since attacker tooling usually follows one quickly.

Why this matters

Two things make this release stand out. First, the scale: three CVEs at 9.9 plus a 9.8 command injection is a large batch of critical issues in core networking gear. Second, the origin: these bugs came from Cisco's own security review assisted by frontier AI models. Internal discovery beats the alternative, but it also signals more of these findings are coming.

History also argues for speed. Cisco's network management software has been a recurring target: the 2023 IOS XE web interface campaign infected tens of thousands of devices, and in early 2026 a Five Eyes advisory warned operators to patch an actively exploited Cisco SD-WAN flaw. Network gear like this gets patched slowly, and when a batch of 9.9 and 9.8 ratings goes public, attacker tooling tends to follow. A quiet advisory today can become an emergency CISA KEV entry in a few months.

Frequently Asked Questions

Are these Cisco vulnerabilities being exploited in the wild? Cisco states it has no awareness of malicious use so far, and no public exploit codes exist for the hardening bugs. The IMC issue is the exception, with a public proof-of-concept available.

What is the most dangerous CVE in this batch? CVE-2026-20079 in FMC is rated 10.0 and needs no authentication. Among the network-adjacent flaws, the 9.8 command injection in IOS XE (CVE-2026-20272) is the one most likely to be dangerous in practice.

Which IOS XE software versions fix these issues? Fixed releases: 17.9.10, 17.12.8, 17.15.6, 17.18.4 or 17.18.4a, and 26.1.2.

Is there a workaround? No. Cisco says there are no workarounds. You upgrade to the fixed release, and Cisco-managed cloud SD-WAN instances were updated automatically.

Who found these vulnerabilities? Cisco's security engineering teams, using the company's own testing processes and AI-based review models. The only externally reported item here is the IMC argument injection, from assessment by NSIDE ATTACK LOGIC.

Do I need to patch if my SD-WAN is in the cloud? No. Cisco managed cloud-SD-WAN has been updated automatically. On-premises Catalyst SD-WAN controllers and management planes still need manual action.

Key takeaways

  • Cisco fixed 12 vulnerabilities in two advisories for Catalyst SD-WAN and Cisco IOS XE on August 5, 2026.
  • The five Catalyst SD-WAN CVE groups (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313) include three 9.9 critical ratings.
  • The seven IOS XE CVE groups include a 9.8 command injection and a 9.0 access control flaw.
  • The same batch fixed a 10.0 authentication bypass in FMC (CVE-2026-20079) and IMC command injection with a public PoC (CVE-2026-20200).
  • No workarounds exist for the hardening batches; a fixed software path is mandatory.
  • Book a change window, test one upgrade train first, then roll out the fix. Doing it now is cheaper than doing it after the first incident report shows up.

Conclusion

Cisco's August 5 security release is a reminder that the enterprise edge stays at risk even when no new attack is in the news. If you run IOS XE or Catalyst SD-WAN, the plan is simple: test one release train, then roll out the fix across your fleet. Doing it now is cheaper than doing it after the first incident report shows up.


Sources: Cisco Catalyst SD-WAN Hardening Advisory Cisco IOS XE Hardening Advisory Cisco IMC CVE-2026-20200 Advisory SecurityWeek Help Net Security Field Effect

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links