CVE-2026-20303 – Cisco Catalyst SD-WAN Controller

CVSS 9.9 CRITICAL Critical - Same Day Deployment

“Proactive security reviews are most valuable when they eliminate critical weaknesses before attackers can exploit them.”

Cisco has released software hardening updates for the Cisco Catalyst SD-WAN Controller to address multiple internally discovered vulnerabilities identified during a comprehensive security review. The updates resolve issues involving improper input validation, improper access control, improper link resolution before file access, and cleartext storage of sensitive information, improving the overall resilience of the platform.

CVE-2026-20303 has a CVSS score of 9.9, Critical severity. CVE-2026-20304 has a CVSS score of 9.9, Critical severity. CVE-2026-20310 has a CVSS score of 9.1, Critical severity. CVE-2026-20312 has a CVSS score of 8.8, High severity. CVE-2026-20313 has a CVSS score of 7.7, High severity. No verified public proof-of-concept code or real-world exploitation has been confirmed for these vulnerabilities.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.