Cisco has released patches for roughly two dozen vulnerabilities spanning Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC), among other products, with several flaws rated critical severity.

Catalyst SD-WAN

Five fixes address multiple weaknesses grouped by vulnerability class. Three carry a CVSS score of 9.9: CVE-2026-20303 (improper input validation), CVE-2026-20304 (improper access control), and CVE-2026-20310 (improper link resolution before file access). Two additional high-severity issues, CVE-2026-20312 (cleartext storage of sensitive information) and CVE-2026-20313 (improper validation of specified quantity in input), were also patched.

IOS XE

Seven fixes were issued for IOS XE, again grouped by underlying vulnerability class. CVE-2026-20272, a command injection flaw scoring 9.8, and CVE-2026-20267, an improper access control issue scoring 9.0, are rated critical. The remaining IOS XE fixes address high-severity flaws.

Secure Firewall Management Center

The standout fix is CVE-2026-20079, a critical authentication bypass in FMC with a maximum CVSS score of 10. Cisco says a remote, unauthenticated attacker could send crafted HTTP requests to an affected device and execute scripts and commands that grant root-level access, effectively taking full control of the system.

Other affected products

Cisco also patched high-severity issues in Integrated Management Controller (IMC), IOS XE, and IOS, along with medium-severity bugs in IOS XE, Terminal Service (TS) Agent, Catalyst SD-WAN Manager, RoomOS, and IMC.

One issue warrants particular attention: CVE-2026-20200, a high-severity improper input validation flaw in IMC scoring 8.8. It could allow an authenticated attacker to remotely execute arbitrary commands and gain root privileges. Cisco notes that proof-of-concept code targeting this vulnerability already exists, even though exploitation requires authentication. The flaw affects UCS C-Series M7 and M8 Rack Servers running in standalone mode.

No known exploitation

Cisco states it is not aware of any of these vulnerabilities being exploited in the wild. Administrators running affected Catalyst SD-WAN, IOS XE, FMC, or IMC deployments should prioritize patching, particularly for the critical-severity flaws in SD-WAN and FMC, and review the company’s security advisories page for full remediation guidance.