Cisco patches critical flaws in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center

Cisco released security updates for two dozen vulnerabilities, including critical flaws that could let attackers take over network management and firewall systems. The most severe is CVE-2026-20079, a CVSS 10 authentication bypass in Secure Firewall Management Center that allows remote unauthenticated attackers to send crafted HTTP requests and gain root access. Cisco also fixed critical Catalyst SD-WAN bugs including CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, plus critical IOS XE issues CVE-2026-20272 and CVE-2026-20267; PoC exploit code exists for IMC flaw CVE-2026-20200 affecting UCS C-Series M7 and M8 Rack Servers in standalone mode.
Why it matters: These are core enterprise network and security products, so a successful exploit could give attackers deep control over important systems. Organizations using the affected Cisco products should review Cisco's advisories and patch promptly, especially FMC, SD-WAN, IOS XE, and exposed IMC deployments.

Sources

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Ionut Arghire 2026.08.06 100% relevant
This article establishes a distinct Cisco patch-release event covering newly disclosed critical flaws in Catalyst SD-WAN, IOS XE, Secure Firewall Management Center, and IMC, and it is not the same underlying event as the previously tracked Cisco SD-WAN zero-day or FMC exploitation stories.
← Back to all stories