CVE-2026-20304 – Cisco Catalyst SD-WAN Controller

CVSS 9.9 CRITICAL 2 Critical – Same Day Deployment

“Critical weaknesses in a central network controller can put access controls, sensitive data, and core infrastructure at risk.”

Cisco software hardening releases address five internally discovered vulnerabilities in Catalyst SD-WAN Controller. CVE-2026-20303 has a CVSS score of 9.9, Critical severity, and involves improper input validation. CVE-2026-20304 has a CVSS score of 9.9, Critical severity, and involves improper access control. CVE-2026-20310 has a CVSS score of 9.1, Critical severity, and affects link resolution before file access.

CVE-2026-20312 has a CVSS score of 8.8, High severity, and involves cleartext storage of sensitive information. CVE-2026-20313 has a CVSS score of 7.7, High severity, and involves improper link resolution. Cisco's software hardening releases address these controller weaknesses.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-284
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.