rootpwn

Advisories

Cisco Catalyst SD‑WAN Hardening Update: Critical Vulnerabilities Resolved (CVE‑2026‑20303‑20313)

Cisco’s SD‑WAN software team released a hardening patch in August 2026 after an internal audit uncovered several critical weaknesses. Five CVEs—CVE‑2026‑20303, ‑20304, ‑20310, ‑20312, ‑20313—were addressed through a single update per CWE class. No workarounds exist, so all Catalyst SD‑WAN customers should apply the new releases immediately to close the gaps.

Cisco’s Catalyst SD‑WAN engineering squad conducted a comprehensive internal security review and identified a handful of high‑impact vulnerabilities. The company grouped these weaknesses by Common Weakness Enumeration (CWE) categories and assigned one CVE identifier to each group. The resulting hardening releases patch the five CVEs listed below.

Fixed CVEs

  • CVE-2026-20303
  • CVE-2026-20304
  • CVE-2026-20310
  • CVE-2026-20312
  • CVE-2026-20313

Security Impact Rating: Critical

There are no known workarounds for these issues; the only remediation is to apply the updated firmware. Cisco urges all Catalyst SD‑WAN customers to download and install the latest patches as soon as possible.

"We remain committed to proactive security and product quality, and we thank our customers for their cooperation as we continue to strengthen our solutions."

Cisco SD‑WAN Security Hardening CVE Critical Vulnerabilities

← All news