Cisco Addresses Catalyst SD-WAN Software Multiple Vulnerabilities (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, & CVE-2026-20313)

Cisco released a security advisory addressing five vulnerabilities affecting Catalyst SD-WAN Software. Three of these vulnerabilities have been given a critical severity rating with a CVSS score of 9.9.

These vulnerabilities were disclosed during internal testing conducted by the Cisco team. The vulnerabilities are not known to be exploited in the wild.

Cisco Catalyst SD-WAN Manager is a centralized network management system (NMS) that provides a single pane of glass to configure, monitor, and troubleshoot an entire SD-WAN fabric. It serves as the orchestration and management plane of the Cisco Catalyst SD-WAN architecture.

Vulnerability Details

CVE-2026-20303

This is an improper input validation flaw that may lead to path traversal and external path control.

CVE-2026-20304

This is an improper access control flaw that may lead to authentication bypass and privilege escalation.

CVE-2026-20310

This is an improper link resolution before the file access flaw.

CVE-2026-20312

This is a clear-text storage of sensitive information flaw.

CVE-2026-20313

This is an improper validation of specified quantity in input flaw.

Affected and Patched Versions

These vulnerabilities affect all Cisco Catalyst SD-WAN Manager, regardless of device configuration.

The vulnerabilities affect all deployment types, including:

  • On-Prem Deployment
  • Cisco SD-WAN Cloud-Pro
  • Cisco SD-WAN Cloud (Cisco Managed)
  • Cisco SD-WAN for Government (FedRAMP)
Affected Version First Fixed Release
Earlier than 20.91 Migrate to a fixed release.
20.9 20.9.10
20.10 20.12.8.1
20.11 20.12.8.1
20.12 20.12.8.1
20.13 20.15.6
20.14 20.15.6
20.15 20.15.6
20.16 20.18.4
20.18 20.18.4
26.1 26.1.2

NOTE: The release versions 20.11, 20.13, 20.14, 20.16 have reached End of Software Maintenance. Cisco urges users to migrate to a supported release.

Customers can refer to the Cisco Security Advisory (cisco-sa-hardening-sdwan-faLcR3K) for information about the vulnerability.

Qualys Detection

Qualys customers can scan their devices with QID 317869 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K