CVE-2026-20303 – Cisco Catalyst SD-WAN Controller
“Proactive security reviews are most valuable when they eliminate critical weaknesses before attackers can exploit them.”
Cisco has released software hardening updates for the Cisco Catalyst SD-WAN Controller to address multiple internally discovered vulnerabilities identified during a comprehensive security review. The updates resolve issues involving improper input validation, improper access control, improper link resolution before file access, and cleartext storage of sensitive information, improving the overall resilience of the platform.
CVE-2026-20303 has a CVSS score of 9.9, Critical severity. CVE-2026-20304 has a CVSS score of 9.9, Critical severity. CVE-2026-20310 has a CVSS score of 9.1, Critical severity. CVE-2026-20312 has a CVSS score of 8.8, High severity. CVE-2026-20313 has a CVSS score of 7.7, High severity. No verified public proof-of-concept code or real-world exploitation has been confirmed for these vulnerabilities.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-20