Skip to content
VulniPulse
Highest advisory severityCritical 1 vendor · 2 advisories

CVE-2026-20304

CVE-2026-20304: 2 tracked advisory records across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

2 advisories
  • Advisory severityCritical9.9

    Critical [CVE-2026-20303 +4] Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

    cisco-sa-hardening-sdwan-faLcR3KSource published Source updated

    This bulletin covers 5 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address…

    Affected products in this advisory
    • Catalyst SD-WAN Controller
    • Catalyst SD-WAN Manager
    Source-reported affected versions
    • Scope: These vulnerabilities affect Cisco Catalyst SD-WAN Software, regardless of device configuration.
    • Earlier than 20.91 — Migrate to a fixed release
    • Release 20.9 (first fixed: 20.9.10)
    • Release 20.10 (first fixed: 20.12.8.1)

    8 more entries in the full advisory.

    Source-reported fixed versions
    • 20.9.10
    • 20.12.8.1
    • 20.15.6
    • 20.18.4

    1 more entries in the full advisory.

    Mitigation guidance
    • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
    • Earlier than 20.91: migrate to a fixed release.
    • Release 20.9: upgrade to 20.9.10.
    • Release 20.10: upgrade to 20.12.8.1.

    5 more entries in the full advisory.

    Workarounds
    • There are no workarounds that address these vulnerabilities.
  • Advisory severityHigh

    High [CVE-2026-20028 +21] Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

    cisco-sa-notice-L4XfJg8SSource published Source updated

    This bulletin covers 22 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20312 CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273 Critical 9.8 Cisco Integrated Management Controller Argument Injection Vulnerabilities CVE-2026-20200 CVE-2026-20288 High 8.8 Cisco IOS Software and IOS XE Software Extensible…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst SD-WAN Integrated Management Controller (IMC) IOS Software IOS XE Software RoomOS Terminal Services Agent To fully remediate vulnerabilities to be disclosed on August 5, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery