CVE-2026-20303Patch

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 8 signals
  • Disclosure: 2 classified signals
  • Peaked 8d ago at 2 mentions (2026-08-05); latest day: 2
  • 13 total mentions across 9 days

Deep dive

Activity timeline13 mentions / 9d
01122Mentions · 2026-08-05: 2Mentions · 2026-08-06: 1Mentions · 2026-08-07: 2Mentions · 2026-08-11: 1Mentions · 2026-08-13: 2Mentions · 2026-08-14: 1Mentions · 2026-08-17: 1Mentions · 2026-08-18: 1Mentions · 2026-08-19: 2PoC Mentioned / Linked · 2026-08-11: 1Exploit Tool / Code · 2026-08-11: 1Patch / Workaround · 2026-08-05: 2Patch / Workaround · 2026-08-07: 2Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-13: 2Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-17: 1Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-13: 2Technical Details · 2026-08-14: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 108-0508-0608-0708-1108-1308-1408-1708-1808-19
Signal classification2 categories
Patch
1184.6%
Disclosure
215.4%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-052
Patch2
2026-08-061
Disclosure1
2026-08-072
Patch2
2026-08-111
Patch1
2026-08-132
Patch2
2026-08-141
Patch1
2026-08-171
Patch1
2026-08-181
Patch1
2026-08-192
Disclosure1Patch1
Full discourse13 posts
  • 横浜539@PutStickerOn
    Patch

    > IOS XEでは7件の脆弱性が修正され、CVE-2026-20272(中略)とCVE-2026-20267(中略)は深刻度が「Critical」、残り5件は「High」となっている。 なんと。 シスコ、SD-WANやIOS XEなど複数製品の深刻な脆弱性を多数修正(CVE-2026-20303、CVE-2026-20304他) https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47119/

    Post summary

    Cisco released patches for seven IOS XE vulnerabilities, including two rated Critical and five rated High, without discussing exploitability or providing technical details.

    0301062.2K
    3.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Cisco SD-WAN vulnerability CVE-2026-20303 and CVE-2026-20304 reach CVSS 9.9. Cisco urges Catalyst SD-WAN customers to patch now. #Cisco #SDWAN #CVE202620303 #CVE202620304 #CyberSecurity #NetworkSecurity http://securityonline.info/cisco-sd-wan-cve-2026-20303/

    Post summary

    The tweet announces severe Cisco SD‑WAN CVEs with a high CVSS score and urges customers to apply the available patch immediately.

    00021454
    13.0K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Cisco Catalyst SD-WAN の複数の深刻な脆弱性が FIX:不適切な入力検証やアクセス・コントロール https://iototsecnews.jp/2026/08/06/cisco-patched-multiple-critical-vulnerabilities-in-catalyst-sd-wan-update-now/ Cisco Catalyst SD-WAN Software において、入力検証の不備やアクセス制御の問題などに起因する複数の深刻な脆弱性が発見されました。対象となる CVE は CVE-2026-20303/CVE-2026-20304/CVE-2026-20310 (CVSS:9.9)、CVE-2026-20312 (CVSS:8.8)、CVE-2026-20313 (CVSS:7.7) です。これらを悪用されると、機密情報の露出や不正なファイルアクセスなど、システム全体へ甚大な被害が及ぶ恐れがあります。回避策となる設定変更が存在しないため、修正済みバージョンへのアップデートが必要です。運用環境の更新状況を確認し、迅速に対応を進めてください 。 #CatalystSDWAN #Cisco #CVE202620303 #CVE202620304 #CVE202620310 #CVE202620312 #CVE202620313 #Vulnerability

    Post summary

    Cisco Catalyst SD‑WAN has multiple critical vulnerabilities (CVE‑2026‑20303/04/10/12/13) with high CVSS scores; no workaround exists, and users are urged to update to patched versions as soon as possible.

    01001182
    507 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    Cisco Catalyst SD-WANにCVSS 9.9の脆弱性3件、修正版へ更新 https://www.cybernote.click/2026/08/13/cisco-catalyst-sd-wan-cve-2026-20303-20304-20310-hardening/ #IT #Security #cybersecurity

    Post summary

    The article reports three CVSS 9.9 vulnerabilities in Cisco Catalyst SD‑WAN and notes that a patched version is available.

    00010129
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-20303 CiscoのCisco IOSに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/08/12/cve-2026-20303-cisco-ios/ #IT #Security #cybersecurity

    Post summary

    The post announces a new critical vulnerability (CVE-2026-20303) in Cisco IOS and urges immediate action, but provides no detailed technical or exploit information.

    00010121
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    Cisco Catalyst SD-WANにCVSS 9.9の脆弱性3件、修正版へ更新 https://www.cybernote.click/2026/08/13/cisco-catalyst-sd-wan-cve-2026-20303-20304-20310-hardening/ #IT #Security #cybersecurity

    Post summary

    Three high‑severity CVEs (CVE‑2026‑20303, CVE‑2026‑20304, CVE‑2026‑20310) in Cisco Catalyst SD‑WAN have been addressed with a patch; no report of active exploitation or PoC was found.

    0001063
    212 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    Cisco Catalyst SD-WANにCVSS 9.9の脆弱性3件、修正版へ更新 https://www.cybernote.click/2026/08/13/cisco-catalyst-sd-wan-cve-2026-20303-20304-20310-hardening/ #IT #Security #cybersecurity

    Post summary

    The tweet announces that three high‑CVSS vulnerabilities in Cisco Catalyst SD‑WAN have been fixed with an update.

    0000049
    210 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    Cisco Catalyst SD-WANにCVSS 9.9の脆弱性3件、修正版へ更新 https://www.cybernote.click/2026/08/13/cisco-catalyst-sd-wan-cve-2026-20303-20304-20310-hardening/ #IT #Security #cybersecurity

    Post summary

    Three high‑severity CVEs (2026‑20303, 20304, 20310) identified in Cisco Catalyst SD‑WAN; a repair update is suggested, but no details on attack techniques or active exploitation are disclosed.

    0000069
    210 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    Cisco Catalyst SD-WANにCVSS 9.9の脆弱性3件、修正版へ更新 https://www.cybernote.click/2026/08/13/cisco-catalyst-sd-wan-cve-2026-20303-20304-20310-hardening/ #IT #Security #cybersecurity

    Post summary

    Three new CVEs (cve-2026-20303, 20304, 20310) with a CVSS score of 9.9 affecting Cisco Catalyst SD‑WAN are now patched in the latest firmware update.

    0000092
    213 followersView on X
  • BT Haberler@BTHaberler
    Patch

    Cisco, SD-WAN ve IOS XE'de Üçü CVSS 9.9 Olan 12 Kritik Açığı Kapattı Cisco, iç güvenlik incelemesi kapsamında Catalyst SD-WAN ve IOS XE yazılımlarını etkileyen 12 açığı kapatan güncellemeler yayınladı; SD-WAN tarafındaki üç açık maksimuma yakın CVSS 9.9 aldı! • CVE-2026-20303, CVE-2026-20304 ve CVE-2026-20310 (üçü de CVSS 9.9), sırasıyla giriş doğrulaması ve yol geçişi eksikliği, yetersiz erişim kontrolü ve bağlantı çözümleme sırası hatasından kaynaklanıyor; ayrıca CVSS 8.8'lik açık metin hassas veri depolama sorunu da bulunuyor. • IOS XE tarafında CVE-2026-20267 ile CVE-2026-20273 arasındaki yedi açık, arabellek taşması, komut enjeksiyonu ve giriş doğrulaması eksikliklerini kapsıyor; en yüksek CVSS puanı 9.8. • Cisco, bu açıkların şu ana kadar aktif olarak istismar edildiğine dair bir bilgi bulunmadığını açıkladı; ancak sistem yönetim arabirimini etkileyen ayrı bir açık olan CIMCown (CVE-2026-20200) için halka açık kanıt kodu zaten mevcut. Kurumsal ağların omurgasını oluşturan SD-WAN ve yönlendirici yazılımlarında aynı anda bu kadar çok maksimum puanlı açığın ortaya çıkması, ağ ekiplerinin güncelleme önceliklerini yeniden gözden geçirmesini gerektiriyor. #SiberGüvenlik #Cisco #SDWAN

    Post summary

    Cisco released updates that address 12 high‑severity SD‑WAN and IOS XE vulnerabilities, verified by a publicly available proof‑of‑concept for CVE‑2026‑20200, with no evidence of active exploitation.

    00000128
    38 followersView on X
  • Machina Record@MachinaRecord
    Patch

    🔨シスコ、SD-WANやIOS XEなど複数製品の深刻な脆弱性を多数修正(CVE-2026-20303、CVE-2026-20304他) ⚠️中国Zbtlink製ルーターにバックドア 〜サイバーアラート8月7日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47119/

    Post summary

    Cisco has released patches for several severe vulnerabilities (CVE‑2026‑20303, CVE‑2026‑20304, etc.) affecting SD‑WAN and IOS XE, while a backdoor was discovered in Chinese Zbtlink routers.

    00000209
    1.3K followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-20303およびCVE-2026-20304:Cisco SD-WANの脆弱性がCVSSスコア9.9に該当 CVE-2026-20303 & CVE-2026-20304: Cisco SD-WAN Flaws Hit CVSS 9.9 #DailyCyberSecurity (Aug 5) https://securityonline.info/cisco-sd-wan-cve-2026-20303/

    Post summary

    The post announces two Cisco SD‑WAN CVEs (2026‑20303 and 2026‑20304) with a high CVSS score of 9.9, but provides no further technical, exploit, or patch details.

    00000337
    4.9K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Patch

    🚨 CRITICAL — CVE-2026-20303 Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVSS 9.9 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-20303 #Cisco #CyberSecurity #InfoSec

    Post summary

    CVE-2026-20303 is a critical vulnerability (CVSS 9.9) with no patch available yet.

    0000055
    88 followersView on X

Explore more