Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical

An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

ThreatVectr Newsdesk· 3 min read
Close-up overhead shot of a dense rack of enterprise networking and telephony hardware, blinking amber and red indicator lights visible across multiple units, s
Share

Key points

  • Cisco released fixes for 12 vulnerabilities in Catalyst SD-WAN Software and IOS XE Software, three of them rated 9.8 out of 10 on the CVSS severity scale.
  • The flaws were uncovered during an internal Cisco security review, not by an outside attacker exploiting them in the wild.
  • Catalyst SD-WAN devices are affected regardless of configuration, and IOS XE is affected when running in autonomous or controller mode.
  • Cisco has not reported any active exploitation, but the high scores mean network administrators are expected to patch quickly.
  • The advisories apply to equipment used by large enterprises, telecom carriers and government agencies.

Cisco has published a batch of software updates covering 12 security holes in two of its most widely deployed networking products. Three of the flaws carry the highest severity rating the industry uses, a CVSS score of 9.8 out of 10, meaning they are easy to exploit remotely and give attackers deep access.

CVSS, short for the Common Vulnerability Scoring System, is the standard yardstick vendors and regulators use to rank how dangerous a software bug is.

The affected products are Cisco Catalyst SD-WAN Software, which stitches together a company's branch offices over the internet, and Cisco IOS XE Software, the operating system running on many Cisco routers and switches. The company says Catalyst SD-WAN is at risk regardless of how a device is set up. IOS XE is only at risk when running in what Cisco calls autonomous or controller mode, two configurations common in enterprise networks.

Cisco says the bugs surfaced during a company-led security review of its own code, not from an outside report or an intrusion. That distinction matters. It means there is no known attack in the wild yet, and defenders have a head start.

Who is affected?

Organisations running Cisco Catalyst SD-WAN or IOS XE routers and switches. That covers a large share of corporate, telecom and government networks. Home users and small businesses on consumer routers are not in scope.

Administrators should check the version numbers on their Cisco gear against the fixed releases listed in Cisco's advisories and schedule the update. The critical-rated flaws could, in the worst case, let an unauthenticated attacker run their own commands on the device, meaning they would not need a password to take control.

Should ordinary customers do anything?

Not directly. These are network-operator products, not something a member of the public installs. The patching work sits with the IT teams at banks, hospitals, universities, internet providers and the like. If those teams delay, the knock-on risk is service disruption or a breach at an organisation that holds your data.

As first reported by The Hacker News, the release includes 12 separate advisories tied to this internal review, with severity ratings ranging from medium up to the three critical entries.

What the numbers look like

Item Detail
Total vulnerabilities patched 12
Critical (CVSS 9.8) 3
Affected products Catalyst SD-WAN Software, IOS XE Software
IOS XE modes at risk Autonomous, controller
Known exploitation None reported by Cisco

Why this matters for policy watchers

Critical flaws in core routing software are exactly the class of issue that trigger obligations under recent disclosure regimes. Publicly traded companies operating this gear should be reviewing whether an unpatched, exploitable instance would qualify as a material cybersecurity risk under existing Securities and Exchange Commission rules on incident reporting. Federal civilian agencies, for their part, patch on the timelines set by the Cybersecurity and Infrastructure Security Agency's binding operational directives when a matching entry is added to the Known Exploited Vulnerabilities catalog. No such addition has been announced at the time of writing.

The practical read: patch on Cisco's schedule now, do not wait for a regulator to force the point.

© 2026 Threat Vectr