Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks
Cisco has released critical security updates for its Catalyst SD-WAN Software after discovering several high-severity vulnerabilities. The flaws, which were found during internal security testing using advanced AI models, could allow attackers to bypass access controls, escalate privileges, and expose sensitive data.
The most severe vulnerabilities have a maximum CVSS v3.1 score of 9.9 and are identified as CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310. These vulnerabilities were found in various CWE classes, including improper access control, input validation, and link resolution.
Cisco has assigned individual CVE identifiers to several underlying flaws based on their Common Weakness Enumeration (CWE) classes. However, it is essential to note that the listed score for each CVE reflects the highest potential severity within that category, not necessarily a single independent vulnerability.