Cisco has released security updates addressing 24 vulnerabilities across multiple enterprise products, including several critical-severity flaws affecting Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The most severe vulnerability, CVE-2026-20079, impacts FMC and carries a CVSS score of 10.0, enabling unauthenticated remote attackers to bypass authentication and gain root-level access. Cisco has also disclosed critical flaws in IOS XE and Catalyst SD-WAN that could allow command injection, privilege escalation, and unauthorized access.

Although Cisco states it is not aware of active exploitation in the wild, one vulnerability affecting Cisco IMC has publicly available proof-of-concept (PoC) code, increasing the likelihood of future exploitation attempts.

Key Findings

Critical Authentication Bypass in Cisco FMC

CVE-2026-20079
CVSS Score: 10.0 (Critical)

A vulnerability in Cisco Secure Firewall Management Center allows a remote, unauthenticated attacker to send crafted HTTP requests that bypass authentication controls and execute scripts with root privileges. Successful exploitation provides attackers with complete administrative control over the affected system.

Potential Impact

  • Full device compromise
  • Unauthorised script execution
  • Root-level access
  • Network security management takeover
  • Potential lateral movement within enterprise environments

Critical Vulnerabilities in Cisco IOS XE

Cisco addressed seven vulnerabilities in IOS XE, including:

CVE

CVSS

Description

CVE-2026-20272

9.8

Command Injection

CVE-2026-20267

9.0

Improper Access Control

These vulnerabilities could allow attackers to execute unauthorised commands or bypass security controls, leading to device compromise.

Critical Vulnerabilities in Catalyst SD-WAN

Cisco patched five SD-WAN vulnerabilities, including three critical issues:

CVE

CVSS

Vulnerability Type

CVE-2026-20303

9.9

Improper Input Validation

CVE-2026-20304

9.9

Improper Access Control

CVE-2026-20310

9.9

Improper Link Resolution Before File Access

Additional high-severity vulnerabilities:

  • CVE-2026-20312: Cleartext storage of sensitive information
  • CVE-2026-20313: Improper validation of input quantity
  • Unauthorised access to SD-WAN infrastructure
  • Exposure of sensitive configuration data
  • Arbitrary file access
  • Network service disruption

Potential Impact

High-Severity Cisco IMC Vulnerability with Public PoC

CVE-2026-20200
CVSS Score: 8.8

Cisco highlighted a high-severity vulnerability in the Integrated Management Controller (IMC) affecting UCS C-Series M7 and M8 Rack Servers operating in standalone mode. The flaw allows authenticated attackers to execute arbitrary commands and obtain root privileges. Importantly, Cisco confirmed that public proof-of-concept code is available, increasing the risk of exploitation.

Threat Assessment

Likelihood of Exploitation: HIGH

Factors increasing risk include:

  • Multiple vulnerabilities rated Critical (9.0 - 10.0 CVSS).
  • Network-facing attack surfaces, particularly FMC and SD-WAN deployments.
  • Availability of public PoC code for CVE-2026-20200.
  • High value of affected systems for both espionage and ransomware operators.

Business Impact: HIGH

Successful exploitation could result in:

  • Complete compromise of network management infrastructure
  • Privilege escalation to root/system level
  • Unauthorized modification of network configurations
  • Service disruption and operational downtime
  • Lateral movement into enterprise environments

Recommendations:

  1. Upgrade all Cisco Catalyst SD-WAN deployments to the latest fixed software version, with priority given to internet-facing management interfaces and systems affected by the critical vulnerabilities. Recommended fixed releases include 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2. Environments running versions earlier than 20.9 should be upgraded or migrated to a supported release.
  2. Review and strengthen SD-WAN access controls, as successful exploitation requires authenticated, low-privileged access. Apply the principle of least privilege, remove unused or dormant accounts, and limit management-plane access to only those users who require it.
  3. Implement compensating controls where patching cannot be performed immediately. Restrict administrative access to SD-WAN controllers through VPN-only connectivity, enforce IP allowlisting, and minimize exposure of management interfaces until remediation is completed.

 If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation. 

 

Contact Us