Cisco Patches Critical Vulnerabilities Across SD-WAN, IOS XE, and IMC Software
Cisco has released a series of critical security updates to address multiple high-severity vulnerabilities impacting its **Catalyst SD-WAN Software**, **IOS XE Software**, and **Integrated Management Controller (IMC)**. These flaws, discovered during internal security testing and not yet actively exploited, could lead to arbitrary command execution, privilege escalation, and sensitive data exposure, necessitating immediate patching for IT security professionals.
Network equipment giant **Cisco** has issued comprehensive security updates to mitigate several critical vulnerabilities across its product lines, including **Catalyst SD-WAN Software**, **IOS XE Software**, and the **Integrated Management Controller (IMC)**.
These vulnerabilities were identified through **Cisco**'s internal security testing, which included the use of frontier AI models. **Cisco** has confirmed there is no evidence of active exploitation for these specific flaws, but strongly urges customers to apply the necessary patches without delay.

## Critical Flaws in Catalyst SD-WAN Software
The **Cisco Catalyst SD-WAN Software** is affected by multiple high-severity vulnerabilities, irrespective of device configuration. These include:
* **CVE-2026-20303** (CVSS: 9.9) - An improper input validation vulnerability, covering path traversals.
* **CVE-2026-20304** (CVSS: 9.9) - An improper access control vulnerability.
* **CVE-2026-20310** (CVSS: 9.9) - An improper link resolution before file access vulnerability.
* **CVE-2026-20312** (CVSS: 8.8) - A cleartext storage of sensitive information vulnerability.
* **CVE-2026-20313** (CVSS: 7.7) - An improper validation of specified quantity in input.
Patches for these issues are available in **Cisco Catalyst SD-WAN Software** versions 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2. Users on earlier versions are advised to migrate to a fixed release.
## Significant Vulnerabilities in IOS XE Software
**Cisco IOS XE Software**, when operating in autonomous or controller mode, is also subject to a suite of vulnerabilities related to improper access control, command injection, and input validation. Key vulnerabilities include:
* **CVE-2026-20267** (CVSS: 9.0) - An improper access control vulnerability.
* **CVE-2026-20268** (CVSS: 8.6) - A set of buffer overflow and out-of-bounds write vulnerabilities.
* **CVE-2026-20269** (CVSS: 8.6) - An improper control of a resource through its lifetime vulnerability.
* **CVE-2026-20270** (CVSS: 8.6) - An incorrect calculation vulnerability, including arithmetic and numeric conversion errors.
* **CVE-2026-20271** (CVSS: 8.6) - An insufficient control flow management vulnerability, covering infinite loops, uncontrolled recursion, and race conditions.
* **CVE-2026-20272** (CVSS: 9.8) - An improper neutralization of special elements vulnerability, encompassing command, operating system, and argument injection.
* **CVE-2026-20273** (CVSS: 8.6) - An improper input validation vulnerability, including path traversals.
These seven flaws have been addressed in **Cisco IOS XE Software** versions 17.9.10, 17.12.8, 17.15.6, 17.18.4, 17.18.4a, and 26.1.2.
## IMC Flaws and PoC Exploit Availability
Separately, **Cisco** has also released fixes for high-severity vulnerabilities in the web-based management interface of its **Integrated Management Controller (IMC)**. Notably, a proof-of-concept (PoC) exploit is publicly available for **CVE-2026-20200**.
* **CVE-2026-20200** (CVSS: 8.8) - An improper validation of user-supplied input that could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system and elevate privileges to root.
* **CVE-2026-20288** (CVSS: 6.5) - Another improper validation of user-supplied input that could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands and elevate privileges to root.
Security researcher **Christoph Peil**, who discovered and reported **CVE-2026-20200**, emphasized the gravity of an **IMC** compromise: "The controller sits in a position where it can influence the BIOS and SecureBoot and interact with the operating system above it. An attacker who gains root here can thereby nest themselves deeply and persistently in the system β far below what classic protective measures such as EDR solutions at the operating-system level can even see. The trust anchor of the entire server hardware is thus compromised."
This round of disclosures follows a recent warning from **Cisco** regarding the active exploitation of **CVE-2026-20316** (CVSS: 5.3), a vulnerability in **Cisco Secure Firewall Management Center (FMC) Software** that allows low-privilege accounts to access sensitive data.
IT security professionals and privacy-conscious users are strongly advised to review their **Cisco** deployments and apply all relevant updates immediately to protect against potential exploitation.