In brief: Cisco has patched twelve vulnerabilities in Catalyst SD-WAN and IOS XE software, three of them with a critical CVSS score of 9.8.
As part of an internal security review, Cisco has released patches for twelve vulnerabilities in Catalyst SD-WAN Software and IOS XE Software. Three of the flaws reach the critical CVSS score of 9.8.
The affected vulnerabilities were identified by Cisco during an internal security review and concern, on one hand, Catalyst SD-WAN Software regardless of the specific device configuration, and on the other hand, IOS XE Software when operated in autonomous mode or controller mode. In total, Cisco closed twelve security vulnerabilities, with three of them classified as critical due to the maximum CVSS base score of 9.8.
For CISOs at organizations running Cisco network infrastructure with SD-WAN components or IOS XE in controller configuration, immediate action is required. SD-WAN solutions and routers running IOS XE frequently form the backbone of WAN connectivity between sites and to cloud environments. Vulnerabilities with a CVSS score of 9.8 typically indicate a compromise that is remotely exploitable without authentication and has a high impact on confidentiality, integrity, and availability, even though Cisco does not specify detailed attack vectors or concrete CVE numbers in the cited source.
Operations teams should consult the full Cisco security advisory overview to determine the exact CVE identifiers, affected software versions, and available fixed releases. Since the vulnerabilities affect both Catalyst SD-WAN and IOS XE in autonomous and controller mode, an inventory of all deployed devices and software versions is recommended in order to prioritize patching according to the respective network exposure. Until the updates are applied, organizations should assess whether temporary compensating measures, such as restricting management access, would be advisable.
Source: thehackernews.com · Published August 6, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.