Cisco Issues Critical Security Advisories for IOS XE and SD-WAN Vulnerabilities

Cisco Issues Critical Security Advisories for IOS XE and SD-WAN Vulnerabilities

First seen 6 Aug 2026, 15:39 UTC CybersecuritynewsGbhackersFeeds2.FeedburnerDigital.Nhs.Ukwww.ncsc.gov.uk+2 87% similarity 74.0

Article Content

Browse articles
ThreatCluster

Cisco has released critical security advisories for multiple vulnerabilities affecting its IOS XE and Catalyst SD-WAN Software. The advisories, published on August 5, 2026, detail vulnerabilities that could allow attackers to bypass security controls, execute arbitrary commands, and gain unauthorized access. Key vulnerabilities include CVE-2026-20272 for IOS XE with a CVSS score of 9.8, and CVE-2026-20304 for SD-WAN, also with a CVSS score of 9.9. Cisco confirmed that there is currently no evidence of active exploitation for these vulnerabilities. The advisories emphasize the importance of patching affected systems promptly, as edge devices are often targeted by attackers. Organizations are urged to follow NCSC-UK's guidance on vulnerability management. Additional vulnerabilities in Cisco's Integrated Management Controller (IMC) were also disclosed, with a public proof-of-concept exploit available.

Key Points: • Cisco released critical advisories for IOS XE and SD-WAN vulnerabilities on August 5, 2026. • CVE-2026-20272 and CVE-2026-20304 have CVSS scores of 9.8 and 9.9, respectively. • No active exploitation of these vulnerabilities has been confirmed, but patching is strongly advised.

ThreatCluster AI How this analysis works

Timeline

2026-08-05
Cisco publishes advisories for IOS XE and SD-WAN vulnerabilities
Cisco released critical advisories addressing multiple vulnerabilities in IOS XE and SD-WAN Software, urging immediate patching.
Digital.Nhs.Uk
2026-08-05
CVE-2026-20272 published
CVE-2026-20272, a critical command injection vulnerability in IOS XE, was disclosed with a CVSS score of 9.8.
Gbhackers
2026-08-05
CVE-2026-20304 published
CVE-2026-20304, a critical vulnerability in SD-WAN, was disclosed with a CVSS score of 9.9.
Gbhackers
2026-08-05
CVE-2026-20312 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-05
CVE-2026-20303 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-05
CVE-2026-20273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-05
CVE-2026-20270 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-05
CVE-2026-20271 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-05
CVE-2026-20310 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-05
CVE-2026-20313 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →