Cisco Patches Critical Vulnerabilities in Catalyst SD-WAN Software
Cisco has released critical software updates to address multiple vulnerabilities in its Catalyst SD-WAN platform. The flaws were discovered internally by Cisco's engineering team, and there is currently no evidence of active exploitation in the wild.
The most severe issues have a CVSS score of 9.9, just shy of the maximum possible rating. Three critical vulnerabilities affect the platform: improper input validation (CVE-2026-20303), improper access control (CVE-2026-20304), and improper link resolution before file access (CVE-2026-20310).
Cisco has patched multiple vulnerabilities in its Catalyst SD-WAN Software, with no workarounds available. The company urges administrators to prioritize patching immediately, as the flaws represent a significant risk.