V
A
U
L
T
S
H
A
R
E
Cyber Security

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

Cisco has released updates addressing multiple critical security vulnerabilities in Catalyst SD-WAN and IOS XE Software, including three with a 9.8 CV...

By Vaultshare
August 7, 2026 • 4 min read

Overview

Cisco has rolled out a comprehensive set of updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software. The patches, part of a broader internal security review, cover a total of 12 flaws, with three carrying the maximum severity rating of 9.8 on the CVSS scale.

Affected Products

The security issues affect two primary product families:

  • Cisco Catalyst SD-WAN Software – Vulnerable regardless of device configuration.
  • Cisco IOS XE Software – Affected when running in either autonomous or controller mode.

This broad scope means a wide range of enterprise networking devices are potentially exposed, including routers, switches, and wireless controllers that rely on these software platforms.

Critical Vulnerabilities

Among the 12 flaws patched, three have been assigned a CVSS score of 9.8, classifying them as critical. While the specific technical details of these vulnerabilities are not fully disclosed in the initial advisory, their severity indicates that they could be exploited remotely with high impact on confidentiality, integrity, and availability. The remaining nine vulnerabilities vary in severity but collectively pose a significant risk to network infrastructure.

Impact and Risks

If left unpatched, these vulnerabilities could allow attackers to compromise network devices, potentially leading to unauthorized access, data exfiltration, or disruption of network services. Because the flaws affect both Catalyst SD-WAN and IOS XE in different operating modes, organizations using these platforms are strongly advised to assess their exposure and prioritize remediation.

Recommendations

Cisco urges customers to apply the latest software updates immediately. Organizations should also review their security advisories for detailed mitigation steps and indicators of compromise. The discovery of these flaws during a comprehensive internal security review underscores the importance of continuous vulnerability assessment and proactive patch management in maintaining network resilience.

“These vulnerabilities were found during a comprehensive internal security review,” a Cisco advisory stated, highlighting the company’s ongoing commitment to identifying and resolving security weaknesses before they can be exploited.

Network administrators are advised to monitor Cisco’s official security advisory pages for updates and to test patches in a controlled environment before deploying them across production networks.