Multiple security vulnerabilities affecting Cisco Catalyst SD-WAN Controller versions The flaws hit Cisco Catalyst SD-WAN releases before the fixed builds have been identified in Cisco Catalyst SD-WAN Controller, affecting every deployment type including on-prem, cloud, and FedRAMP government setups. The flaws impact the core of many corporate WANs, threatening traffic routing across enterprise networks. Affected versions include releases before fixed builds.
CVE-2026-20303 (CVSS 9.9 — Critical): This flaw stems from improper input validation, also covering path traversal and external path control.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Cisco Catalyst SD-WAN Controller versions The flaws hit Cisco Catalyst SD-WAN releases before the fixed builds have been identified in Cisco Catalyst SD-WAN Controller, affecting every deployment type including on-prem, cloud, and FedRAMP government setups. The flaws impact the core of many corporate WANs, threatening traffic routing across enterprise networks. Affected versions include releases before fixed builds.
CVE-2026-20303 (CVSS 9.9 — Critical): This flaw stems from improper input validation, also covering path traversal and external path control.[emaillocker id="1283"]
CVE-2026-20304 (CVSS 9.9 — Critical): This bug breaks authorization and authentication, allowing attackers to bypass privilege checks.
CVE-2026-20310 (CVSS 9.1 — High): Improper link resolution before file access is involved in this flaw.
CVE-2026-20312 (CVSS 8.8 — Medium): Cleartext secrets are exposed through this vulnerability.
CVE-2026-20313 (CVSS 7.7 — Low): Input quantity validation mishandling is the issue with this flaw.
These vulnerabilities collectively present a significant risk to corporate WANs, particularly those relying on Cisco Catalyst SD-WAN Controller.
We recommend you to update Cisco Catalyst SD-WAN Controller to version 20.9.10, 20.12.8.1 or 20.15.6, depending on your installed branch, 20.18.4, or 26.1.2.
The following reports contain further technical details:
[/emaillocker]