Skip to content
VulniPulse

Cisco SD-WAN Vulnerabilities & Security Advisories

12 advisories tracked · Cisco Security Advisories · 6 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Cisco advisory that VulniPulse classified as SD-WAN, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 3 high, 4 medium.

Android app · Google Play

Monitor Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Cisco Security Advisories

Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.

Latest Cisco SD-WAN advisories

Medium6.5Cisco

Medium [CVE-2026-20294] Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVE-2026-20294
SD-WANCatalyst SD-WAN
Aug 5, 2026
Medium4.3Cisco

Medium [CVE-2026-20308] Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected products named by the advisory: Aironet Access Point Software (IOS XE Controller); IOS XE Catalyst SD-WAN; IOS XE Software Bootloader (ROMMON); IOS XG Software; and 1 more.

CVE-2026-20308
SD-WANRoutersWirelessIOS XE
Aug 5, 2026
Medium6.5Cisco Exploited CISA KEV

Medium [CVE-2026-20262] Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least write access. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVE-2026-20262
SD-WANCatalyst SD-WANvManage
Jun 15, 2026
Medium5.4Cisco

Medium [CVE-2026-20108] Cisco Catalyst SD-WAN Manager Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based informatio…

CVE-2026-20108
SD-WANCatalyst SD-WAN
Mar 25, 2026

← All Cisco advisories