Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
AI-summarised brief · reviewed before publication
Cisco has released security updates for Catalyst SD‑WAN and IOS XE software after an internal review uncovered twelve critical flaws, including three with a CVSS rating of 9.8. The patches address improper access control, command injection, and input‑validation errors in IOS XE, and multiple vulnerabilities in SD‑WAN that affect all device configurations. Cisco also fixed a high‑severity bug in the Integrated Management Controller’s web UI (CVE‑2026‑20200), for which a proof‑of‑concept exploit exists and could let an attacker gain root access, compromising BIOS, SecureBoot and the server’s trust anchor. The company warned that none of the flaws are known to be actively exploited, but urged immediate deployment. This follows a recent alert about active exploitation of a lower‑severity firewall management vulnerability (CVE‑2026‑20316).
💡 Why It Matters
- · Exploiting the IMC flaw would let attackers embed themselves below OS‑level defenses, undermining the hardware root of trust across Cisco‑based networks.