429/69 Friday, August 7, 2026

Cisco has released security updates to address vulnerabilities in enterprise networking and security management products, including Cisco Catalyst SD-WAN, Cisco IOS XE, and Cisco Secure Firewall Management Center (FMC). The updates include Critical vulnerabilities that could be exploited to escalate privileges, execute commands, or access affected systems if attackers meet the required exploitation conditions.
Reports indicate that Cisco Catalyst SD-WAN received fixes in the August 2026 Security Hardening Release, with a CVSS severity score of 9.9. Cisco IOS XE also received fixes as part of a Security Hardening Release, with a CVSS severity score of 9.8. In addition, Cisco updated information and remediation guidance for vulnerabilities in Cisco Secure FMC, including CVE-2026-20079, an authentication bypass vulnerability that could allow unauthenticated attackers to execute scripts on the system and gain root privileges, as well as CVE-2026-20316, a static credential vulnerability that has reportedly been actively exploited in attacks.
Administrators using Cisco products should review the security advisories related to Catalyst SD-WAN, IOS XE, and Secure FMC, check the software versions in use, and update to fixed versions as soon as possible. Some vulnerabilities do not have temporary mitigations that can fully replace applying updates. Administrators should also restrict access to management interfaces from the internet, review logs and abnormal activity on network management systems, and use Cisco Software Checker or organizational patch management tools to assess the risk of each system.
Source: https://www.securityweek.com/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities/
