Cisco Rolls Out Patches for Dozens of Critical Vulnerabilities
Cisco has released patches for two dozen vulnerabilities across its products, including critical-severity bugs in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC).
The company released five fixes for Catalyst SD-WAN, noting that the CVEs were assigned to multiple weaknesses grouped by the underlying vulnerability class. Three of the CVEs have a CVSS score of 9.9 and are described as improper input validation, improper access control, and improper link resolution before file access.
Cisco also patched seven flaws in IOS XE, including two critical-severity command injection and improper access control defects with CVSS scores of 9.8 and 9.0, respectively. FMC received patches for CVE-2026-20079, a critical authentication bypass that allows remote, unauthenticated attackers to execute scripts and gain root privileges.
Cisco notes that an attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.