Skip to content
Cisco

Cisco Patches Critical SD-WAN, IOS XE, FMC Flaws

Cisco kritieke patches

Cisco has rolled out a new set of software updates to address dozens of security weaknesses across several product lines. Among the fixes are multiple issues rated critical, including flaws tied to Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). For organizations running these platforms, applying the relevant patches should be treated as a priority.

The company’s advisory details how some CVEs are grouped by underlying vulnerability classes, even when separate CVE identifiers point to different weaknesses. That means administrators may need to review multiple security bulletins and verify which devices and versions are affected before upgrading.

What Cisco patched: multiple critical areas

Across the release, Cisco targeted a broad range of products, including Catalyst SD-WAN, IOS XE, FMC, Integrated Management Controller (IMC), and additional components such as Terminal Service (TS) Agent and RoomOS. It also included medium-severity fixes affecting specific environments.

While the patch set is wide, several vulnerabilities stand out due to their severity and the potential impact on confidentiality, integrity, and device control.

Critical fixes for Catalyst SD-WAN

For Catalyst SD-WAN, Cisco published five fixes tied to multiple vulnerabilities grouped by the underlying vulnerability category. Three of the referenced CVEs—CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310—carry a CVSS score of 9.9.

According to Cisco, these issues relate to improper input handling, improper access control, and improper link resolution occurring before file access. In practical terms, that combination can increase the odds that crafted inputs or requests may cause unauthorized access paths or unexpected behavior in how the system resolves and accesses resources.

The remaining two Catalyst SD-WAN CVEs, CVE-2026-20312 and CVE-2026-20313, are rated high severity. Cisco describes them as cleartext storage of sensitive information and improper validation of a specified quantity in user input.

IOS XE receives fixes including command injection

Cisco also released seven fixes for IOS XE, again grouping CVEs by underlying vulnerability classes. Two of these vulnerabilities are critical, with CVSS scores of 9.8 and 9.0.

The critical items include CVE-2026-20272, described as a command injection defect, and CVE-2026-20267, described as an improper access control issue. Cisco also notes that the remaining IOS XE fixes are high severity and fall within other vulnerability categories.

Command injection vulnerabilities are particularly concerning because they can allow an attacker to influence how commands are processed. When paired with access control weaknesses, the likelihood of successful compromise can increase.

FMC patch addresses critical authentication bypass

Perhaps the most urgent item is the FMC vulnerability. Cisco patched CVE-2026-20079, which has a CVSS score of 10. This is described as a critical authentication bypass that can enable remote, unauthenticated attackers to execute scripts and gain root privileges.

Cisco explains that an attacker could attempt exploitation by sending crafted HTTP requests to an affected device. If successful, the attacker may be able to execute a range of scripts and commands that ultimately provide root-level access.

For teams responsible for firewall management, this kind of flaw is especially important because FMC systems often sit at the center of security policy administration. A takeover can mean an attacker may alter or bypass controls, not just probe systems.

Additional high- and medium-severity patches across products

Beyond the headline issues in SD-WAN, IOS XE, and FMC, Cisco also addressed security defects in other platforms and components. High-severity vulnerabilities were patched in IMC, IOS XE, and IOS, while medium-severity bugs were addressed across IOS XE, Terminal Service (TS) Agent, Catalyst SD-WAN Manager, RoomOS, and IMC.

This matters because real-world deployments frequently combine features from multiple product families. Even if your most exposed systems are the first ones you think of, supporting components may still carry exploitable weakness.

Special attention: IMC vulnerability with available PoC

Among the additional issues, Cisco calls out CVE-2026-20000 for special attention. This vulnerability is described as a high-severity improper input validation problem affecting IMC. Cisco warns that it can be exploited remotely to execute arbitrary commands and gain root privileges.

Importantly, Cisco notes that exploitation requires authentication. However, the company also states that proof-of-concept (PoC) code targeting the flaw already exists, which can lower the barrier for attackers and accelerate attempts against exposed systems.

According to the advisory, this weakness affects UCS C-Series M7 and M8 Rack Servers operating in standalone mode. Administrators of these environments should confirm whether their configuration matches the impacted conditions.

Are these Cisco critical vulnerabilities being exploited?

Cisco states that it is not aware of any of the vulnerabilities being exploited in the wild at the time of the advisory. Still, the lack of confirmed active exploitation does not eliminate risk—especially when public PoCs exist for some flaws or when similar vulnerabilities have been targeted historically.

Therefore, a preventive approach is recommended: evaluate exposure, plan the update path, and test patches in a staging environment when possible.

Recommended next steps for administrators

If you manage devices covered by the patched products, consider the following actions to reduce risk quickly:

  • Check your versions and configurations against Cisco security advisories to determine which CVEs apply to your environment.
  • Prioritize the highest severity items, especially critical issues in FMC, IOS XE, and Catalyst SD-WAN.
  • Validate management-plane exposure, since vulnerabilities affecting authentication and access control can be reachable over network interfaces.
  • Plan a controlled rollout that includes testing, change windows, and verification steps after upgrades.
  • Review related components such as IMC and management agents, since medium- and high-severity issues may also be present.

For many organizations, patching is only one part of remediation. Ensuring that administrative access is locked down, monitoring logs for suspicious requests, and using segmentation can further reduce the chance that an attacker can take advantage of a weakness.

Conclusion

Cisco’s latest release addresses multiple Cisco critical vulnerabilities across Catalyst SD-WAN, IOS XE, and FMC, including severe flaws like authentication bypass and command injection. With additional high- and medium-severity fixes spread across IMC and other management components, the safest path is to review the advisories, confirm affected deployments, and apply the appropriate updates without delay.

Even though Cisco reports no known in-the-wild exploitation at the time of publication, the presence of PoC code for at least one issue makes proactive patching and security hardening the most sensible next step.

Source: https://www.securityweek.com/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities/