Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

https://www.securityweek.com/wp-content/uploads/2025/09/Cisco-firewall.jpeg

Cisco on Wednesday rolled out patches for two dozen vulnerabilities across its products, including critical-severity bugs in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC).

For Catalyst SD-WAN, the company released five fixes, noting that the CVEs were assigned to multiple weaknesses grouped by the underlying vulnerability class.

Three of the CVEs, namely CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, have a CVSS score of 9.9 and are described as improper input validation, improper access control, and improper link resolution before file access.

The remaining two, CVE-2026-20312 and CVE-2026-20313, are high-severity flaws described as cleartext storage of sensitive information and improper validation of specified quantity in input.

IOS XE received seven fixes, and the assigned CVEs group multiple issues by their underlying vulnerability class.

Two of them, CVE-2026-20272 (CVSS score of 9.8) and CVE-2026-20267 (CVSS score of 9.0), are critical-severity command injection and improper access control defects, while the rest are...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more