Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Cisco released patches for two dozen vulnerabilities across Catalyst SD-WAN, IOS XE, Secure Firewall Management Center, and other products, including several critical flaws that could allow remote code execution and root access. The most severe issues include CVE-2026-20079 in FMC, multiple high-risk bugs in Catalyst SD-WAN and IOS XE, and a notable IMC flaw affecting UCS C-Series M7 and M8 Rack Servers. #CVE-2026-20079 #CVE-2026-20272 #CVE-2026-20303 #Cisco #CatalystSDWAN #IOSXE #SecureFirewallManagementCenter #IMC #UCSCSeries

Keypoints

  • Cisco patched two dozen vulnerabilities across multiple products.
  • Catalyst SD-WAN received five fixes, including three CVEs with CVSS 9.9.
  • IOS XE received seven fixes, with critical command injection and access control flaws.
  • FMC CVE-2026-20079 is a CVSS 10 authentication bypass that can lead to root access.
  • CVE-2026-20200 affects IMC on UCS C-Series M7 and M8 Rack Servers and has PoC code available.

Read More: https://www.securityweek.com/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities/