Threat reportVulnerabilityTL-2026-1905

Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313)

criticalACTIVE

Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN (TL-2026-1905), also tracked as cisco-sa-hardening-sdwan-faLcR3K, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-08-06. It has no confirmed attribution, affects Cisco Catalyst SD-WAN Controller (formerly vSmart), references 6 CVEs (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310), maps to 9 MITRE ATT&CK techniques (T1005, T1046, T1059), and is covered by 9 detection rules and 11 indicators of compromise.

CVSS
9.9/10Critical
CVEs
6Referenced vulnerabilities
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
11Indicators of compromise

Key facts for TL-2026-1905

Threat ID
TL-2026-1905
Also known as
cisco-sa-hardening-sdwan-faLcR3K, Cisco Catalyst SD-WAN August 2026 Hardening Release
Severity
CRITICAL
CVSS
9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
telecoms, government administration, enterprise, managed-service-providers, energy, finance
Target regions
Global
Detection rules
9
Indicators of compromise
11

How Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN works

Cisco disclosed five internally discovered vulnerabilities in Cisco Catalyst SD-WAN Software, including three critical-severity flaws rated CVSS 9.9 (CVE-2026-20303 improper input validation, CVE-2026-20304 access control bypass, CVE-2026-20310 link resolution) and two high-severity flaws (CVE-2026-20312 CVSS 8.8 cleartext credential exposure, CVE-2026-20313 CVSS 7.7 input quantity validation). All deployment models of SD-WAN Manager and SD-WAN Controller are affected with no workarounds; only software upgrades remediate.

On August 5, 2026, Cisco published Security Advisory cisco-sa-hardening-sdwan-faLcR3K disclosing five vulnerabilities discovered during internal security testing of Cisco Catalyst SD-WAN Software, using a combination of traditional testing processes and frontier AI models. The three critical flaws (CVSS 9.9, vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) require only low-privilege network access with no user interaction and cross trust boundaries (scope changed): CVE-2026-20303 (CWE-20 Improper Input Validation) covers input validation, path traversal, and external path control; CVE-2026-20304 (CWE-284 Improper Access Control) bundles authorization, authentication, and privilege-related bypass issues; CVE-2026-20310 (CWE-59 Improper Link Resolution Before File Access) allows attackers to manipulate symbolic links to reach unintended files. Two additional high-severity flaws complete the set: CVE-2026-20312 (CVSS 8.8, CWE-312) exposes credentials or other secrets in cleartext should the underlying system be compromised, and CVE-2026-20313 (CVSS 7.7, CWE-1284) is an improper validation of specified quantity in input that yields a high availability impact (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H). All deployment models are affected — On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP) — and the affected components are the Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage), spanning versions 17.2.4 through 26.1.1.2. No configuration setting or feature toggle exempts a device from exposure. Cisco states there are no workarounds and no known public announcements or malicious use of these five vulnerabilities as of publication; the advisory warns they could become attractive targets once technical details circulate.

These disclosures arrive against a backdrop of documented state-sponsored exploitation of Cisco SD-WAN infrastructure. In February 2026, CISA issued Emergency Directive 26-03 (Mitigate Vulnerabilities in Cisco SD-WAN Systems) after Mandiant identified a threat actor targeting Cisco Catalyst SD-WAN infrastructure at a service provider, using stolen certificate material to establish rogue peering connections, manipulate the default admin account, and exploit CVE-2026-20245 (a tenant-upload CSV command-injection zero-day) to create a root-level backdoor account (troot). CISA added CVE-2026-20245 and CVE-2026-20262 to the Known Exploited Vulnerabilities catalog in June 2026. While the five CVEs in this advisory are not on the CISA KEV as of August 6, 2026, and no exploitation of these specific flaws has been reported, the demonstrated interest of sophisticated adversaries in SD-WAN control-plane infrastructure makes rapid remediation essential. Cisco's grouping of multiple underlying weaknesses by CWE class under a single CVE per class simplifies disclosure and patching but means each CVE may represent a family of defects across the affected products.

MITRE ATT&CK techniques used in TL-2026-1905

Collection

T1005 Data from Local System

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation

Impact

T1485 Data Destruction

Credential Access

T1552 Unsecured Credentials

Defense Evasion

T1574 Hijack Execution Flow

Affected products and versions in Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN

  • Cisco — Catalyst SD-WAN Controller (formerly vSmart)
    Vulnerable versions: 17.2.4 through 26.1.1.2 (all versions prior to fixed releases)
    Fixed in: 20.9.10; 20.12.8.1; 20.15.6; 20.18.4; 26.1.2
  • Cisco — Catalyst SD-WAN Manager (formerly vManage)
    Vulnerable versions: 17.2.4 through 26.1.1.2 (all versions prior to fixed releases)
    Fixed in: 20.9.10; 20.12.8.1; 20.15.6; 20.18.4; 26.1.2
  • Cisco — SD-WAN Cloud (Cisco Managed)
    Vulnerable versions: All prior versions
    Fixed in: 20.15.602 (no user action required)

Remediation for Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN

Patches

  • Cisco Catalyst SD-WAN Software 20.9 -> 20.9.10
  • Cisco Catalyst SD-WAN Software 20.10/20.11/20.12 -> 20.12.8.1
  • Cisco Catalyst SD-WAN Software 20.13/20.14/20.15 -> 20.15.6
  • Cisco Catalyst SD-WAN Software 20.16/20.18 -> 20.18.4
  • Cisco Catalyst SD-WAN Software 26.1 -> 26.1.2
  • Cisco SD-WAN Cloud (Cisco Managed) 20.15.602 (no user action required)

Immediate actions

  • Apply the fixed software release for the deployment's release train immediately: 20.9.10 (20.9 branch), 20.12.8.1 (20.10-20.12), 20.15.6 (20.13-20.15), 20.18.4 (20.16/20.18), or 26.1.2 (26.1 branch)
  • Restrict network access to SD-WAN Manager (vManage) and SD-WAN Controller (vSmart) management interfaces to trusted administrator networks only; do not expose them to untrusted segments
  • Audit the SD-WAN fabric for unauthorized peering connections, unexpected controller IPs, and unusual peering timestamps
  • Review /var/log/auth.log for anomalous SSH logins and /var/log/scripts.log for abnormal vconfd_script_upload_tenant_list.sh executions

Workarounds

  • None available - Cisco states 'There are no workarounds that address these vulnerabilities.' Only software upgrades remediate.

Longer-term hardening

  • Segment the SD-WAN management plane (Manager, Controller, Validator) from the rest of the network with strict ACLs/firewall rules
  • Deploy centralized logging and alerting for all SD-WAN control components; forward syslog to an external SIEM
  • Implement multi-factor authentication for all administrative access to SD-WAN components and restrict SSH (port 22) and NETCONF (port 830) to known controller IPs
  • Enable configuration integrity monitoring to detect unauthorized changes to /etc/passwd, /etc/shadow, and vbond_vsmart_tenant_list
  • Maintain an accurate inventory of SD-WAN deployments and track which release train each device runs to enable rapid patch rollout

CVEs associated with Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN

CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313, CVE-2026-20245

Weaknesses (CWE) in Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN

CWE-20, CWE-284, CWE-59, CWE-312, CWE-1284

Timeline of Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN

  • Mandiant observes initial unauthorized peering connections on a service provider's Cisco Catalyst SD-WAN infrastructure, beginning a multi-month state-sponsored targeting campaign against SD-WAN control components
  • Cisco Catalyst SD-WAN exploitation activity continues through early 2026; threat actor establishes rogue peer connections using stolen certificate material
  • CISA issues Emergency Directive ED 26-03 (Mitigate Vulnerabilities in Cisco SD-WAN Systems) after active exploitation is documented, requiring FCEB agencies to inventory, patch, and hunt on SD-WAN deployments
  • Mandiant documents threat actor authenticating via SSH as vmanage-admin, changing the default admin password, and extracting SD-WAN fabric configuration via the /dataservice API
  • Threat actor exploits CVE-2026-20245 via the tenant-upload CLI feature, uploading evil_tenant.csv to create a root-level 'troot' backdoor account
  • CISA adds CVE-2026-20262 and CVE-2026-20245 to the Known Exploited Vulnerabilities catalog, both affecting Cisco Catalyst SD-WAN Manager
  • Mandiant/Google Cloud publishes technical report on zero-day exploitation of Cisco Catalyst SD-WAN Manager, revealing the full attack chain and anti-forensic cleanup techniques
  • NVD publishes CVE entries for all five vulnerabilities with Cisco as the source; SSVC assessment by CISA Coordinator records exploitation status 'none' and technical impact 'total' for the critical flaws
  • Cisco publishes Security Advisory cisco-sa-hardening-sdwan-faLcR3K disclosing five internally discovered vulnerabilities (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310 critical CVSS 9.9; CVE-2026-20312 CVSS 8.8; CVE-2026-20313 CVSS 7.7) discovered using traditional testing plus frontier AI models; no active exploitation reported
  • None of the five CVEs are on the CISA Known Exploited Vulnerabilities catalog as of this date; Cisco-managed SD-WAN Cloud customers already received the fix in release 20.15.602 automatically
  • Cybersecurity News reports on the Cisco Catalyst SD-WAN vulnerabilities, noting the AI-assisted discovery method and warning the bugs could become attractive targets once technical details circulate

Sources cited for Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN

Detection coverage for TL-2026-1905

As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1905 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
11 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats