# Cisco Drops Emergency Patches for 12 Flaws Across SD-WAN and IOS XE — Three Score 9.9


## The Threat


Cisco has published fixes for twelve security vulnerabilities spanning its Catalyst SD-WAN platform and IOS XE operating system, with three of the SD-WAN bugs carrying a near-perfect CVSS score of 9.9. The flaws range from improper input validation and path traversal to command injection and cleartext credential storage — a broad attack surface that covers some of the most widely deployed networking infrastructure in enterprise and service provider environments.


What makes this batch unusual is how Cisco found them. The company says the vulnerabilities were discovered through internal security testing augmented by "frontier AI models" — a rare public acknowledgment that AI-assisted fuzzing and code analysis is now part of Cisco's security development lifecycle. None of the flaws are known to be actively exploited, but that window won't stay open indefinitely, particularly given that a proof-of-concept exploit already exists for one of the separately disclosed Integrated Management Controller (IMC) vulnerabilities.


The IOS XE set includes CVE-2026-20272, a command injection flaw scoring 9.8, alongside a cluster of buffer overflows, race conditions, and resource lifecycle issues — all affecting IOS XE running in either autonomous or controller mode. Combined with the SD-WAN flaws, this is one of the larger single-cycle patch drops Cisco has issued for its core networking stack in recent memory.


## Severity and Impact


### Cisco Catalyst SD-WAN


| CVE | CVSS Score | Type | CWE |

|-----|-----------|------|-----|

| CVE-2026-20303 | 9.9 | Improper input validation / path traversal | CWE-20 / CWE-22 |

| CVE-2026-20304 | 9.9 | Improper access control | CWE-284 |

| CVE-2026-20310 | 9.9 | Improper link resolution before file access (symlink) | CWE-59 |

| CVE-2026-20312 | 8.8 | Cleartext storage of sensitive information | CWE-312 |

| CVE-2026-20313 | 7.7 | Improper validation of specified quantity in input | CWE-1284 |


### Cisco IOS XE


| CVE | CVSS Score | Type | CWE |

|-----|-----------|------|-----|

| CVE-2026-20272 | 9.8 | Command / OS / argument injection | CWE-78 |

| CVE-2026-20267 | 9.0 | Improper access control | CWE-284 |

| CVE-2026-20268 | 8.6 | Buffer overflow / out-of-bounds write | CWE-120 / CWE-787 |

| CVE-2026-20269 | 8.6 | Improper control of resource through its lifetime | CWE-664 |

| CVE-2026-20270 | 8.6 | Integer overflow / underflow / truncation | CWE-190 |

| CVE-2026-20271 | 8.6 | Insufficient control flow management (race conditions, infinite loops) | CWE-691 |

| CVE-2026-20273 | 8.6 | Improper input validation / path traversal | CWE-20 / CWE-22 |


### Cisco IMC (Separate Advisory)


| CVE | CVSS Score | Type | Notes |

|-----|-----------|------|-------|

| CVE-2026-20200 | 8.8 | OS command injection via web UI | PoC available; low-privilege remote attacker → root |

| CVE-2026-20288 | 6.5 | OS command injection via web UI | Admin-level attacker → root |


## Affected Products


### Cisco Catalyst SD-WAN Software

All versions are affected regardless of device configuration. Fixed releases:


  • 20.9.x → update to 20.9.10
  • 20.10.x, 20.11.x, 20.12.x → update to 20.12.8.1
  • 20.13.x, 20.14.x, 20.15.x → update to 20.15.6
  • 20.16.x, 20.18.x → update to 20.18.4
  • 26.1.x → update to 26.1.2
  • Earlier than 20.9 → migrate to a fixed release (no patch provided)

  • ### Cisco IOS XE Software

    Affected in both autonomous and controller mode:


  • 17.9.x → update to 17.9.10
  • 17.12.x → update to 17.12.8
  • 17.15.x → update to 17.15.6
  • 17.18.x → update to 17.18.4 or 17.18.4a
  • 26.1.x → update to 26.1.2

  • ### Cisco Integrated Management Controller (IMC)

    Affects the web-based management interface across multiple server product lines. Consult Cisco's IMC advisory for specific affected hardware models and firmware versions.


    ## Mitigations


    Patch immediately. Cisco has made fixed releases available for all supported version branches. The IOS XE command injection bug (CVE-2026-20272, CVSS 9.8) and the three SD-WAN 9.9-scoring flaws represent serious risk to perimeter and backbone infrastructure.


    Where immediate patching isn't possible:


  • Restrict management plane access. Ensure SD-WAN management interfaces and IOS XE management ports are not reachable from untrusted networks. Place them behind out-of-band management VLANs or dedicated management VPNs.
  • IMC web interface. Disable remote access to the IMC web UI if not operationally required. Given that a PoC is already circulating for CVE-2026-20200, this is not optional.
  • Audit credentials. CVE-2026-20312 involves cleartext storage of sensitive information in SD-WAN. After patching, rotate any credentials that may have been stored by the affected component.
  • Monitor for exploitation indicators. While no active exploitation has been confirmed, the availability of PoC code for the IMC vulnerability raises the urgency. Review logs for unexpected authentication attempts or command execution via management interfaces.
  • Legacy version holders. SD-WAN versions earlier than 20.9 receive no patch — migration to a supported branch is the only remediation path.

  • ## References


  • [Cisco Security Advisory: Catalyst SD-WAN Vulnerabilities](https://sec.cloudapps.cisco.com/security/center/publicationListing.x)
  • [Cisco Security Advisory: IOS XE Software Vulnerabilities](https://sec.cloudapps.cisco.com/security/center/publicationListing.x)
  • [Cisco Security Advisory: IMC Web Interface (CVE-2026-20200)](https://sec.cloudapps.cisco.com/security/center/publicationListing.x)
  • [Cisco Software Checker](https://software.cisco.com/download/home)
  • [NIST NVD](https://nvd.nist.gov/)

  • ---


    ## HackWire Analysis


    Two things stand out in this advisory that deserve more attention than a patch-Tuesday headline captures.


    The first is Cisco's explicit acknowledgment that these vulnerabilities were found partly by "frontier AI models." This isn't a throwaway marketing line — it signals that AI-assisted vulnerability discovery is becoming a production-grade tool in enterprise security engineering. The implication cuts both ways: if Cisco's defenders are running AI fuzzers over their own codebase, adversarial teams are running equivalent tools externally. The race to find bugs before the other side does has gotten faster, and the 12-CVE haul from what sounds like a focused internal audit is evidence of what that acceleration looks like in practice.


    The second is the IMC situation. Security researcher Christoph's warning that a compromised IMC can influence BIOS and SecureBoot isn't buried fine print — it describes a path from "authenticated web request" to "persistent firmware-level compromise." CVE-2026-20200 requires only low privileges to reach root on the underlying OS, and a PoC already exists. Organizations running Cisco UCS or other IMC-managed server infrastructure should treat this as a higher-priority patch than its 8.8 score might suggest. Firmware-level implants survive OS reinstalls and are notoriously difficult to detect. The authentication bar being "low privilege" rather than unauthenticated is cold comfort when credentials are routinely harvested through phishing or credential stuffing.


    The broader pattern: Cisco's networking gear — IOS XE in particular — has been a recurring target for nation-state actors. The ArcaneDoor campaign in 2024, the mass exploitation of CVE-2023-20198, and now a fresh slate of access control and command injection bugs in the same product family. Each cycle, the attack surface gets probed more systematically. Defenders running these platforms should treat this patch batch as a forcing function to audit their management plane exposure, not just run the updater.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)