- Cisco disclosed multiple critical vulnerabilities in Catalyst SD-WAN and IOS XE Software, discovered during internal security testing using frontier AI models.
- The flaws include improper input validation, access control issues, and command injection, with CVSS scores up to 9.9 for SD-WAN and 9.8 for IOS XE.
- Separately, Cisco patched an IMC vulnerability (CVE-2026-20200) with a public proof-of-concept exploit, allowing attackers to gain root access on affected servers.
Cisco has rolled out urgent updates to address a dozen critical security vulnerabilities in Catalyst SD-WAN and IOS XE Software, uncovered during an internal security review that leveraged frontier AI models. The vulnerabilities, which include improper input validation, path traversal, and access control flaws, affect both SD-WAN and IOS XE regardless of device configuration.
The company stated that these flaws were found during internal testing and are not known to be actively exploited, though it urged customers to apply fixes immediately. For SD-WAN, five vulnerabilities were identified, with three rated CVSS 9.9, while IOS XE had seven flaws, including a command injection issue (CVE-2026-20272) scored at 9.8.
Cisco also shipped fixes for two IMC vulnerabilities, including CVE-2026-20200 (CVSS 8.8), for which a proof-of-concept exploit is publicly available. Security researcher Christoph Peil warned that compromising the IMC allows an attacker to nest deeply into the system, far below what operating-system-level protections like EDR can detect.
This disclosure comes less than a week after Cisco warned of active exploitation of a separate vulnerability in Secure Firewall Management Center Software.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
