CVE Tools

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

SecurityWeekBy Ionut Arghire

PatchSD-WANIOS XE

Our summary

Cisco has released updates addressing approximately two dozen security vulnerabilities across its product portfolio, including critical defects in Catalyst SD-WAN, IOS XE, and the Secure Firewall Management Center (FMC). Among the highest-risk issues is CVE-2026-20079 in FMC, a CVSS 10 authentication bypass that permits unauthenticated remote attackers to gain root privileges via crafted HTTP requests. The release also covers other severe bugs such as CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 in SD-WAN, along with command injection vulnerabilities like CVE-2026-20272 in IOS XE. While Cisco reports no evidence of active exploitation in the wild, administrators should apply these fixes promptly to mitigate potential compromise.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store