Cisco has patched two dozen vulnerabilities, including critical flaws in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center, in an advisory batch released midweek. The company said it is not aware of any of the vulnerabilities being exploited in the wild, but several carry severity scores in the critical range, several sit in the software that underpins enterprise routing and switching, and one has a publicly available proof-of-concept.
The Critical Catalyst SD-WAN Flaws in This Batch
Cisco delivered five fixes for Catalyst SD-WAN. Three of them — CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 — are rated critical with CVSS 9.9 base scores and stem from improper input validation, improper access control, and improper link resolution before file access. Two additional high-severity flaws cover cleartext storage of sensitive information and improper validation of a specified quantity in input. Because these land in the software that controllers use to orchestrate multiple locations, they target the central point where network policy for many sites is managed end-to-end.
The IOS XE Command Injection and Access Control Fixes
For IOS XE, Cisco delivered seven fixes led by CVE-2026-20272, a critical command injection rated CVSS 9.8, and CVE-2026-20267, an improper-access-control issue rated 9.0, with the remaining fixes high-severity. These flaws sit in the routing and switching operating system that underpins a large share of the enterprise network, where a command injection on the control plane can hand an attacker a foothold on a device trusted to carry traffic across the organization. IOS XE has drawn repeated scrutiny in recent years, and each critical flaw in it raises the patching stakes for every network team running it in production.
The FMC Authentication Bypass and the IMC Flaw With a Public PoC
The batch also patches CVE-2026-20079 in Secure Firewall Management Center, a critical authentication bypass rated CVSS 10 that allows remote, unauthenticated attackers to execute scripts and gain root privileges via crafted HTTP requests; this element of the batch overlaps coverage of the FMC product line from earlier this week and is carried here as context for the wider release. In the Integrated Management Controller, CVE-2026-20200 is a high-severity improper validation of user-supplied input enabling remote arbitrary-command execution and root, affecting UCS C-Series M7 and M8 Rack Servers in standalone mode; this flaw has a public proof-of-concept and requires authentication.
Why the SD-WAN and IOS XE Fixes Are a Patching Priority
The critical unauthenticated flaws in SD-WAN orchestration and IOS XE expose enterprise networks that rely on those platforms for routing and network policy. SD-WAN controllers sit at the core of distributed office connectivity, and a CVSS 9.9 flaw in that software is an attacker-attractive entry point into the corporate WAN. Cisco also patched high-severity defects across the Integrated Management Controller, IOS XE, and IOS, plus medium-severity bugs in IOS XE, the Terminal Service Agent, Catalyst SD-WAN Manager, RoomOS, and the Integrated Management Controller.
Why the PoC-Bearing IMC Flaw Demands Immediate Attention
The Integrated Management Controller command-execution flaw stands out because a working proof-of-concept has been published. The likelihood of a tool building on a public PoC rises quickly, and Cisco’s own guidance treats the affected UCS servers in standalone mode as at risk. For security teams processing this advisory batch, the combination of the CVSS 9.8-9.9 criticals in SD-WAN and IOS XE alongside the PoC’d IMC flaw defines a clear patching prioritization, even with no in-the-wild exploitation reported.
What This Cisco Batch Signals About Network-Control Security
The release touches almost every major product line — Catalyst SD-WAN, IOS XE, IOS, FMC, the Integrated Management Controller, the Terminal Service Agent, Catalyst SD-WAN Manager, and RoomOS — which makes it a rare sweep across both the routing stack and the compute-management layer. Cisco’s statement that none of the flaws has been observed exploited in the wild does not remove the urgency, because the public proof-of-concept on the IMC path lowers the barrier for a working tool, and the unauthenticated criticals in SD-WAN and IOS XE do not need prior access to be reached.
For organizations running Catalyst SD-WAN, IOS XE, or the affected UCS servers in standalone mode, the batch should be treated as a single coordinated update rather than a set of optional fixes, with the network-control software taking priority over the medium-severity items. A critical flaw in the software that manages many sites at once compounds the impact of any single device compromise, so the devices orchestrating connectivity deserve the same patching urgency as the firewalls and servers they connect.
