Skip to content
CC-4825 - Cisco Releases Catalyst SD

CC-4825 - Cisco Releases Catalyst SD

Digital.Nhs.Uk [email protected] (NHS Digital) August 6, 2026

The advisory addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments

The advisory addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments

The following platforms are known to be affected:

Cisco Catalyst SD-WAN Software

These vulnerabilities affect Cisco Catalyst SD-WAN Software, regardless of device configuration.

These vulnerabilities affect all deployment types, including:

Additional Cisco advisories

Alongside the advisory included in this Cyber Alert, Cisco has released critical hardening guidance for Cisco IOS XE Software (covered in Cyber Alert CC-4824 ) and other important security advisories covered in a notification Cisco Advance Notification for Publication of August 5, 2026, Security Advisories .

Cisco has published a security hardening guidance for Cisco Catalyst SD-WAN Software following a comprehensive internal security review. The update addresses multiple vulnerability classes affecting Cisco Catalyst SD-WAN deployments across on-premises, cloud-managed, and government environments. Cisco states that there is currently no evidence of active exploitation.

Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Successful exploitation of the affected vulnerability classes could allow an authenticated attacker to gain elevated privileges , bypass security controls, access sensitive information, manipulate files or system resources, or otherwise compromise the confidentiality, integrity, and availability of Cisco SD-WAN environments. Several vulnerability classes are associated with a maximum CVSS score of 9.9, indicating a potentially severe impact if exploited.

Edge devices often targeted by attackers

Edge devices like Cisco Catalyst SD-WAN are often internet-facing by design and are highly attractive targets to attackers. An increasing number of edge device vulnerabilities disclosed each year are rapidly exploited by attackers. The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.

Organisations are strongly encouraged to follow NCSC-UK's vulnerability management guidance , including patching edge devices as soon as possible if a critical vulnerability is identified.

Affected organisations are urged to review Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 , assess exposure, and prioritise applying relevant updates.

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59.

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284.

Last edited: 6 August 2026 4:04 pm