CVE-2026-20303 & CVE-2026-20304: Cisco SD-WAN Flaws Hit CVSS 9.9
ID: 5e279fb6-1277-5d18-9d5d-a45ce717f8e7
STIX ID: report--5e279fb6-1277-5d18-9d5d-a45ce717f8e7
Feed Name: securityonline.info
Threat Score
**Executive summary:** Cisco published patches for multiple vulnerabilities in Catalyst SD-WAN software — including two critical CVSS 9.9 bugs that can enable input validation failures, path traversal/external path control, and authentication/authorization bypass — affecting on‑prem, cloud, and FedRAMP deployments; Cisco reports no known active exploitation and urges immediate upgrades to the listed fixed releases since no workarounds exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
