Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has released patches to address multiple critical security vulnerabilities affecting its SD-WAN and IOS XE software. These flaws, including several with a CVSS score of 9.8 and 9.9, cover issues like improper input validation, access control, and command injection. The vulnerabilities were discovered internally and are not currently known to be actively exploited, but a proof-of-concept exploit for one vulnerability (CVE-2026-20200) is available. The vulnerabilities could allow attackers to execute arbitrary commands and escalate privileges, potentially compromising the entire server hardware. Users are urged to migrate to a fixed release immediately.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
