Cisco Fixes Critical Flaws in SD-WAN, IOS XE, FMC Products
Cisco has released patches for two dozen vulnerabilities across its products, including critical-severity bugs in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The company fixed five flaws in Catalyst SD-WAN, noting that the CVEs were assigned to multiple weaknesses grouped by the underlying vulnerability class.
Three of the CVEs, namely CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, have a CVSS score of 9.9 and are described as improper input validation, improper access control, and improper link resolution before file access.
IOS XE received seven fixes, with two critical-severity flaws - CVE-2026-20272 (CVSS score of 9.8) and CVE-2026-20267 (CVSS score of 9.0) - described as command injection and improper access control defects. FMC was patched for a single critical authentication bypass vulnerability, CVE-2026-20079, which allows remote attackers to execute scripts and gain root privileges.