"These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models [...] and are not known to be actively exploited," Cisco said, urging customers to apply the necessary updates for optimal protection.
Cisco's internal security review and the scope of affected software
Cisco disclosed a batch of security fixes on August 6, 2026, addressing multiple critical vulnerabilities discovered during an internal security review. The company said the flaws affect Cisco Catalyst SD-WAN Software (regardless of device configuration) and Cisco IOS XE Software when running in autonomous or controller mode. Cisco characterized the findings as the result of internal testing — including use of "frontier AI models" — and emphasized that the issues were not known to be actively exploited at the time of disclosure.
Catalyst SD‑WAN: five CVEs, three rated 9.9 and fixed in specific releases
Cisco listed five vulnerabilities impacting Catalyst SD‑WAN Software:
- CVE-2026-20303 (CVSS 9.9) — improper input validation (including path traversals)
- CVE-2026-20304 (CVSS 9.9) — improper access control
- CVE-2026-20310 (CVSS 9.9) — improper link resolution before file access
- CVE-2026-20312 (CVSS 8.8) — cleartext storage of sensitive information
- CVE-2026-20313 (CVSS 7.7) — improper validation of specified quantity in input
Cisco listed fixed releases for affected SD‑WAN branches. Notable mappings include:
- 20.9 — fixed in 20.9.10
- 20.10, 20.111, 20.12 — fixed in 20.12.8.1
- 20.131, 20.141, 20.15 — fixed in 20.15.6
- 20.161, 20.18 — fixed in 20.18.4
- 26.1 — fixed in 26.1.2
- Versions earlier than 20.9 — Cisco advises migration to a fixed release

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogIOS XE: seven flaws including a 9.8-rated command-injection issue
Cisco also published fixes for seven vulnerabilities in IOS XE Software related to improper access control, command injection, input validation and several resource- and memory-management issues:
- CVE-2026-20267 (CVSS 9.0) — improper access control
- CVE-2026-20268 (CVSS 8.6) — buffer overflow and out-of-bounds write issues
- CVE-2026-20269 (CVSS 8.6) — improper control of a resource through its lifetime
- CVE-2026-20270 (CVSS 8.6) — incorrect calculation (arithmetic/numeric conversion errors)
- CVE-2026-20271 (CVSS 8.6) — insufficient control flow management
- CVE-2026-20272 (CVSS 9.8) — improper neutralization of special elements (covers command, OS, and argument injection)
- CVE-2026-20273 (CVSS 8.6) — improper input validation (including path traversals)
Fixed IOS XE releases identified by Cisco include:
- 17.9 — fixed in 17.9.10
- 17.12 — fixed in 17.12.8
- 17.15 — fixed in 17.15.6
- 17.18 — fixed in 17.18.4 and 17.18.4a
- 26.1 — fixed in 26.1.2
Integrated Management Controller (IMC) web interface: PoC available and root‑level risk
Separately, Cisco shipped fixes for high-severity flaws in the web-based management interface of Integrated Management Controller (IMC). CVE-2026-20200 (CVSS 8.8) is described as an improper validation of user-supplied input that could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system and elevate privileges to root. Cisco acknowledged a proof-of-concept (PoC) exploit is available for CVE-2026-20200.
Cisco also fixed CVE-2026-20288 (CVSS 6.5), an improper validation of user-supplied input that could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system and elevate privileges to root.
Security researcher Christoph Peil, who discovered and reported CVE-2026-20200, explained the systemic impact: "One should be clear about what a compromise of the IMC means: the controller sits in a position where it can influence the BIOS and SecureBoot and interact with the operating system above it. An attacker who gains root here can thereby nest themselves deeply and persistently in the system – far below what classic protective measures such as EDR solutions at the operating-system level can even see. The trust anchor of the entire server hardware is thus compromised."
What this means for technologists, procurement teams, and server administrators
- Technologists and security teams: Cisco urged customers to apply the necessary updates for optimal protection; teams running affected SD‑WAN or IOS XE releases should map their installed versions to the fixed releases Cisco published and apply patches or migrate where advised.
- Procurement and enterprise network managers: Devices running releases earlier than 20.9 on Catalyst SD‑WAN were explicitly flagged for migration to a fixed release; procurement and asset managers should inventory affected devices and plan upgrade windows to reach the fixed versions listed by Cisco.
- Server administrators and platform owners: The availability of a PoC for CVE-2026-20200 and Christoph Peil’s assessment of deep persistence mean that IMC-managed systems warrant immediate attention, because IMC compromise can influence BIOS and SecureBoot and elevate an attacker to root outside typical OS-level protections.
The disclosure arrives less than a week after Cisco warned of active exploitation of CVE-2026-20316 (CVSS 5.3), a vulnerability in Cisco Secure Firewall Management Center Software that could allow a low-privilege account to access sensitive data within affected systems — a reminder, in Cisco’s timeline, that patch distribution and verification remain immediate operational priorities.
Cisco has provided fixed releases for the affected branches of Catalyst SD‑WAN and IOS XE and urged customers to update. The record now set by internal testing — including frontier AI models — and the existence of a PoC for IMC leave system owners with a simple, concrete choice: apply the updates Cisco published or accept the risks those CVEs represent.




