CVE Tools
Back to feed
Patch released SD-WAN rce IOS XE Cisco auth-bypass

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Cisco has released updates addressing approximately two dozen security vulnerabilities across its product portfolio, including critical defects in Catalyst SD-WAN, IOS XE, and the Secure Firewall Management Center (FMC). Among the highest-risk issues is CVE-2026-20079 in FMC, a CVSS 10 authentication bypass that permits unauthenticated remote attackers to gain root privileges via crafted HTTP requests. The release also covers other severe bugs such as CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 in SD-WAN, along with command injection vulnerabilities like CVE-2026-20272 in IOS XE. While Cisco reports no evidence of active exploitation in the wild, administrators should apply these fixes promptly to mitigate potential compromise.