Cisco shipped fixes for 12 vulnerabilities across Catalyst SD-WAN and IOS XE Software, three of them rated 9.9 on the CVSS scale, after an internal security review that used frontier AI models alongside existing testing processes.
The SD-WAN batch includes CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each a 9.9 covering input validation, access control, and link resolution issues, plus CVE-2026-20312 (8.8) and CVE-2026-20313 (7.7). Cisco said the SD-WAN flaws matter regardless of device configuration.
IOS XE patches cover seven issues including CVE-2026-20272 (9.8, command injection), CVE-2026-20267 (9.0, access control), and a string of 8.6-rated buffer overflow, resource lifetime, and input validation problems.
Fixed releases include 20.9.10, 20.12.8.1, 20.15.6, and 20.18.4 for Catalyst SD-WAN, and 17.9.10, 17.12.8, 17.15.6, and 17.18.4 for IOS XE, with 26.1.2 covering both. Cisco said the bugs are not known to be actively exploited but urged customers to update, noting IOS XE is affected in both autonomous and controller modes.
