Cisco closes top-severity holes in SD-WAN and IOS XE, and there is no way around them
Cisco published security updates for Catalyst SD-WAN, IOS XE and the Integrated Management Controller on 5 August 2026. The most severe are three SD-WAN vulnerabilities with a CVSS score of 9.9, an IOS XE vulnerability scored 9.8 covering improper neutralisation of special elements, and an IMC vulnerability scored 8.8 that lets an authenticated attacker execute commands and elevate to root. Cisco states that no workarounds exist, and that fixed releases are available. The company further states that it is not aware of malicious use of any of these vulnerabilities, but that public proof-of-concept exploit code exists for CVE-2026-20200.
What happens technically
The Catalyst SD-WAN advisory covers five vulnerabilities. CVE-2026-20303, CVE-2026-20304 and CVE-2026-20310 all carry a score of 9.9, while CVE-2026-20312 is scored 8.8 and CVE-2026-20313 is scored 7.7. Cisco describes the weaknesses as improper input validation, access control bypass, unsafe link resolution, cleartext storage of sensitive data and inadequate quantity validation in inputs. Affected releases are Catalyst SD-WAN earlier than 20.91, covering versions from 20.9 through 26.1 across all deployment types, meaning on-premises, cloud and FedRAMP. A score of 9.9 combined with a requirement for low privileges means in practice that a user with limited access can get remarkably far. It is worth remembering what this component does. The SD-WAN controller decides how traffic moves between locations, and control over it is control over the links themselves.
For IOS XE the advisory covers seven vulnerabilities. CVE-2026-20272 is the most severe at 9.8, covering improper neutralisation of special elements, a category that includes command, operating system and argument injection. CVE-2026-20267 is scored 9.0, and the remaining five are scored 8.6. Affected releases are 17.9, 17.12, 17.15, 17.18 and 26.1, in both autonomous and controller mode. The Integrated Management Controller vulnerabilities are of a different kind. CVE-2026-20200 is scored 8.8 and requires an authenticated user with low privileges, while CVE-2026-20288 is scored 6.5 and requires administrator rights. Both let the attacker execute arbitrary commands on the underlying operating system and elevate to root, through improper validation in the web-based management interface. The IMC is the management controller in the hardware itself, and access there sits beneath the operating system the organisation runs and monitors.
The exploitation status deserves a precise distinction. Cisco states that its product security incident response team is not aware of public announcements or malicious use of any of these vulnerabilities. For CVE-2026-20200 Cisco nonetheless states that public proof-of-concept exploit code is available. Known code without known exploitation means the barrier to getting started is low, not that someone has already done it. Cisco states that no workarounds exist for any of the advisories, so updating is the only route. For customers with cloud-managed SD-WAN, Cisco states that the fix was applied automatically.
What this means for you if you run Cisco equipment
This is the equipment that holds your organisation together. An SD-WAN controller decides how traffic moves between offices, data centres and cloud. An IOS XE device is often the same box that terminates the connection out of the building. A management controller such as the IMC gives access beneath the operating system, that is, to the layer where your ordinary security tooling sees nothing at all. When all three receive fixes at once, and none of them has a workaround, this is a task for the change process and not for a free afternoon. Berigo has previously covered a Cisco SD-WAN zero-day that was actively exploited and a static account in Cisco Secure FMC. The pattern is familiar, and it is the repetition that makes it worth taking seriously.
The most important point here, in our view, is that the order matters more than the speed. Start with the IMC, because Cisco states that public exploit code exists, and because management controllers in practice often sit with old passwords and broader network access than anyone decided to give them. Take SD-WAN next, since a score of 9.9 requiring only low privileges lands hard in an environment where many people hold an account. Plan IOS XE as a prioritised but ordinary maintenance round. Use the occasion to check something else at the same time, namely who can reach your management interfaces at all. Such interfaces should not be reachable from the entire internal network, and they should never be reachable from the internet. If your organisation is covered by NIS2, this concerns article 21 and the security of network and information systems, and an audit trail showing when the fix was actually applied.
Berigo recommends
- Update the Integrated Management Controller first, since Cisco states that public exploit code exists for CVE-2026-20200.
- Move Catalyst SD-WAN to 20.91 or later, and verify that cloud-managed installations actually received the fix.
- Plan the IOS XE update as a controlled change, since Cisco states that no workarounds exist.
- Restrict who can reach the management interfaces, and keep the management network separate from the user network.
- Document when the fixes were applied, so the trail exists on the day somebody asks for it.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch