Cisco has released security updates addressing 24 vulnerabilities across multiple enterprise products, including several critical-severity flaws affecting Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The most severe vulnerability, CVE-2026-20079, impacts FMC and carries a CVSS score of 10.0, enabling unauthenticated remote attackers to bypass authentication and gain root-level access. Cisco has also disclosed critical flaws in IOS XE and Catalyst SD-WAN that could allow command injection, privilege escalation, and unauthorized access.
Although Cisco states it is not aware of active exploitation in the wild, one vulnerability affecting Cisco IMC has publicly available proof-of-concept (PoC) code, increasing the likelihood of future exploitation attempts.
CVE-2026-20079
CVSS Score: 10.0 (Critical)
A vulnerability in Cisco Secure Firewall Management Center allows a remote, unauthenticated attacker to send crafted HTTP requests that bypass authentication controls and execute scripts with root privileges. Successful exploitation provides attackers with complete administrative control over the affected system.
Potential Impact
Critical Vulnerabilities in Cisco IOS XE
Cisco addressed seven vulnerabilities in IOS XE, including:
|
CVE |
CVSS |
Description |
|
CVE-2026-20272 |
9.8 |
Command Injection |
|
CVE-2026-20267 |
9.0 |
Improper Access Control |
These vulnerabilities could allow attackers to execute unauthorised commands or bypass security controls, leading to device compromise.
Cisco patched five SD-WAN vulnerabilities, including three critical issues:
|
CVE |
CVSS |
Vulnerability Type |
|
CVE-2026-20303 |
9.9 |
Improper Input Validation |
|
CVE-2026-20304 |
9.9 |
Improper Access Control |
|
CVE-2026-20310 |
9.9 |
Improper Link Resolution Before File Access |
Additional high-severity vulnerabilities:
Potential Impact
CVE-2026-20200
CVSS Score: 8.8
Cisco highlighted a high-severity vulnerability in the Integrated Management Controller (IMC) affecting UCS C-Series M7 and M8 Rack Servers operating in standalone mode. The flaw allows authenticated attackers to execute arbitrary commands and obtain root privileges. Importantly, Cisco confirmed that public proof-of-concept code is available, increasing the risk of exploitation.
Likelihood of Exploitation: HIGH
Factors increasing risk include:
Successful exploitation could result in:
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.