# Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313)

> Cisco disclosed five internally discovered vulnerabilities in Cisco Catalyst SD-WAN Software, including three critical-severity flaws rated CVSS 9.9 (CVE-2026-20303 improper input validation, CVE-2026-20304 access control bypass, CVE-2026-20310 link resolution) and two high-severity flaws (CVE-2026-20312 CVSS 8.8 cleartext credential exposure, CVE-2026-20313 CVSS 7.7 input quantity validation). All deployment models of SD-WAN Manager and SD-WAN Controller are affected with no workarounds; only software upgrades remediate.

- **Published:** 2026-08-06T00:00:00Z
- **Last reviewed:** 2026-08-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1905
- **ID:** TL-2026-1905
- **Severity:** CRITICAL (CVSS 9.9)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313, CVE-2026-20245

## Description

On August 5, 2026, Cisco published Security Advisory cisco-sa-hardening-sdwan-faLcR3K disclosing five vulnerabilities discovered during internal security testing of Cisco Catalyst SD-WAN Software, using a combination of traditional testing processes and frontier AI models. The three critical flaws (CVSS 9.9, vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) require only low-privilege network access with no user interaction and cross trust boundaries (scope changed): CVE-2026-20303 (CWE-20 Improper Input Validation) covers input validation, path traversal, and external path control; CVE-2026-20304 (CWE-284 Improper Access Control) bundles authorization, authentication, and privilege-related bypass issues; CVE-2026-20310 (CWE-59 Improper Link Resolution Before File Access) allows attackers to manipulate symbolic links to reach unintended files. Two additional high-severity flaws complete the set: CVE-2026-20312 (CVSS 8.8, CWE-312) exposes credentials or other secrets in cleartext should the underlying system be compromised, and CVE-2026-20313 (CVSS 7.7, CWE-1284) is an improper validation of specified quantity in input that yields a high availability impact (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H). All deployment models are affected — On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP) — and the affected components are the Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage), spanning versions 17.2.4 through 26.1.1.2. No configuration setting or feature toggle exempts a device from exposure. Cisco states there are no workarounds and no known public announcements or malicious use of these five vulnerabilities as of publication; the advisory warns they could become attractive targets once technical details circulate.

These disclosures arrive against a backdrop of documented state-sponsored exploitation of Cisco SD-WAN infrastructure. In February 2026, CISA issued Emergency Directive 26-03 (Mitigate Vulnerabilities in Cisco SD-WAN Systems) after Mandiant identified a threat actor targeting Cisco Catalyst SD-WAN infrastructure at a service provider, using stolen certificate material to establish rogue peering connections, manipulate the default admin account, and exploit CVE-2026-20245 (a tenant-upload CSV command-injection zero-day) to create a root-level backdoor account (troot). CISA added CVE-2026-20245 and CVE-2026-20262 to the Known Exploited Vulnerabilities catalog in June 2026. While the five CVEs in this advisory are not on the CISA KEV as of August 6, 2026, and no exploitation of these specific flaws has been reported, the demonstrated interest of sophisticated adversaries in SD-WAN control-plane infrastructure makes rapid remediation essential. Cisco's grouping of multiple underlying weaknesses by CWE class under a single CVE per class simplifies disclosure and patching but means each CVE may represent a family of defects across the affected products.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1098 Account Manipulation
- T1574 Hijack Execution Flow
- T1552 Unsecured Credentials
- T1046 Network Service Discovery
- T1005 Data from Local System
- T1485 Data Destruction

## Sources

- [Cisco Security Advisory cisco-sa-hardening-sdwan-faLcR3K](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K)
- [NVD - CVE-2026-20303](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20303)
- [NVD - CVE-2026-20304](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20304)
- [NVD - CVE-2026-20310](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20310)
- [NVD - CVE-2026-20312](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20312)
- [NVD - CVE-2026-20313](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20313)
- [Cybersecurity News - Cisco Catalyst SD-WAN Vulnerabilities](https://cybersecuritynews.com/cisco-catalyst-sd-wan-vulnerabilities-2/)
- [Mandiant/Google Cloud - Zero-Day Exploitation of Cisco Catalyst SD-WAN Manager](https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager)
- [BleepingComputer - Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access](https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/)
- [CISA Emergency Directive ED 26-03 - Mitigate Vulnerabilities in Cisco SD-WAN Systems](https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems)
- [CISA Alert - Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems](https://www.cisa.gov/news-events/alerts/2026/02/25/cisa-and-partners-release-guidance-ongoing-global-exploitation-cisco-sd-wan-systems)
- [SecurityWeek - Cisco SD-WAN Zero-Day Exploited Months Before Patching](https://www.securityweek.com/cisco-sd-wan-zero-day-exploited-months-before-patching/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1905
