Cisco patches critical SD-WAN, IOS XE and FMC flaws

Cisco released patches for two dozen vulnerabilities, including CVE-2026-20079 (CVSS 10) in Secure Firewall Management Center that can allow unauthenticated attackers to gain root access.

Cisco released patches on Wednesday for about two dozen vulnerabilities across its product portfolio, addressing critical flaws in Catalyst SD-WAN, IOS XE and Secure Firewall Management Center (FMC), including one rated CVSS 10.

Five fixes were issued for Catalyst SD-WAN. Three defects-CVE-2026-20303, CVE-2026-20304 and CVE-2026-20310-carry CVSS scores of 9.9 and are described as improper input validation, improper access control and improper link resolution before file access. Two additional SD-WAN issues, CVE-2026-20312 and CVE-2026-20313, are rated high and concern cleartext storage of sensitive information and improper validation of a specified quantity in input.

IOS XE received seven fixes that group multiple issues by underlying vulnerability class. Two are rated critical: CVE-2026-20272, a command injection vulnerability with a CVSS score of 9.8, and CVE-2026-20267, an improper access control defect with a CVSS score of 9.0. The remaining IOS XE fixes are listed as high severity.

FMC was patched for CVE-2026-20079, an authentication bypass with a CVSS score of 10. Cisco’s advisory notes that an attacker could exploit the flaw by sending crafted HTTP requests to an affected device, which could allow execution of scripts and commands that provide root privileges.

The update package also addresses high-severity issues in Integrated Management Controller (IMC), IOS XE and IOS, and medium-severity bugs in IOS XE, Terminal Service Agent, Catalyst SD-WAN Manager, RoomOS and IMC. One high-severity IMC issue, CVE-2026-20200 (CVSS 8.8), involves improper validation of user-supplied input and could be exploited to execute arbitrary commands and obtain root privileges; exploitation requires authentication but proof-of-concept code is publicly available. That IMC vulnerability affects UCS C-Series M7 and M8 Rack Servers operating in standalone mode.

Cisco reports it is not aware of any of the patched vulnerabilities being actively exploited. Its security advisories group several CVEs by underlying vulnerability class and list affected software versions, available workarounds and links to updates.

Administrators running FMC, IOS XE, Catalyst SD-WAN or affected IMC systems should review Cisco’s advisories and apply vendor updates, prioritizing CVE-2026-20079 and the other critical fixes.

Articles by this author