Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical

An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A network operations center displaying SD-WAN infrastructure diagrams with twelve vulnerability indicators highlighted across the topology, three of them marked
Share

Key points

  • Cisco released fixes for 12 vulnerabilities in SD-WAN and IOS XE Software, three of them rated 9.8 out of 10 on the CVSS severity scale.
  • The flaws were uncovered during an internal Cisco security review, not by an outside attacker exploiting them in the wild.
  • Cisco's SD-WAN devices are affected regardless of configuration; IOS XE is at risk only when running in autonomous or controller mode.
  • Cisco has not reported any active exploitation, but the high scores mean network administrators are expected to patch quickly.
  • The advisories apply to equipment used by large enterprises and government agencies.

Cisco has published software updates covering 12 security holes in two of its most widely deployed networking products. Three of the flaws carry a CVSS score of 9.8 out of 10, meaning they're easy to exploit remotely and give attackers deep access.

CVSS, the Common Vulnerability Scoring System, is the standard yardstick vendors and regulators use to rank how dangerous a software bug is. We covered Cisco's previous major patch round on 6 August, when a firewall management flaw scored a rare perfect 10.

The affected products are Cisco's SD-WAN Software, which stitches together a company's branch offices over the internet, and IOS XE Software, the operating system on many Cisco routers and switches. SD-WAN is at risk regardless of how a device is set up. IOS XE is vulnerable only when running in autonomous or controller mode, two configurations common in enterprise networks.

Cisco says the bugs surfaced during a company-led review of its own code, not from an outside report or an intrusion. There's no known attack in the wild yet, so defenders have a head start.

Who is affected?

Organisations running Cisco SD-WAN or IOS XE routers and switches. That covers a large share of corporate and government networks. Home users on consumer routers aren't in scope.

Administrators should check version numbers on their Cisco gear against the fixed releases in Cisco's advisories and schedule the update. The critical-rated flaws could, in the worst case, let an unauthenticated attacker run their own commands on a device without needing a password.

Should ordinary customers do anything?

Not directly. These are network-operator products. The patching sits with IT teams at banks, hospitals and internet providers. Delay the patch, and the knock-on risk is service disruption or a breach at an organisation that holds your data.

As first reported by The Hacker News, the release includes 12 separate advisories, with severity ratings from medium up to the three critical entries.

What the numbers look like

Item Detail
Total vulnerabilities patched 12
Critical (CVSS 9.8) 3
Affected products SD-WAN Software, IOS XE Software
IOS XE modes at risk Autonomous, controller
Known exploitation None reported by Cisco

Why this matters for policy watchers

Critical flaws in core routing software trigger obligations under recent disclosure regimes. Publicly traded companies running this gear should be reviewing whether an unpatched, exploitable instance qualifies as a material cybersecurity risk under SEC incident-reporting rules. Federal civilian agencies patch on timelines set by CISA's binding operational directives once a matching entry lands in the Known Exploited Vulnerabilities catalog. No such entry has been added at the time of writing.

The practical read: patch on Cisco's schedule now. Don't wait for a regulator to force the point.

© 2026 Threat Vectr