
Cisco ships August hardening updates for critical SD-WAN and IOS XE vulnerabilities
Cisco's August PSIRT release fixes critical SD-WAN and IOS XE vulnerabilities found in internal testing with AI models.
Cisco has published a new August security bundle that gives network teams fixed software for a broad set of internally discovered vulnerabilities in Catalyst SD-WAN Software and IOS XE Software. The two critical advisories were first published on August 5, 2026, and sit alongside a wider Cisco PSIRT publication that also lists high- and medium-severity issues across other products.
The most urgent item for SD-WAN operators is Cisco's Catalyst SD-WAN Software Security Hardening Release. Cisco assigns the advisory a maximum CVSS base score of 9.9 and says the affected software is vulnerable regardless of device configuration. The covered deployment types include on-premises SD-WAN, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud, and Cisco SD-WAN for Government. The CVEs are grouped by weakness class rather than by each underlying bug, covering issues such as improper input validation, improper access control, link-resolution flaws, cleartext storage of sensitive information, and quantity validation problems.
IOS XE also received a critical hardening release, with a maximum CVSS base score of 9.8. Cisco says the vulnerabilities affect IOS XE when it is running in autonomous or controller mode, regardless of configuration. The IOS XE advisory groups seven CVEs across classes including access-control weaknesses, memory-buffer errors, resource-lifetime problems, calculation errors, control-flow weaknesses, injection issues, and input-validation flaws.
What Cisco says administrators should do
- For Catalyst SD-WAN, Cisco lists fixed releases including 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2, depending on the currently installed branch.
- For IOS XE, Cisco lists fixed releases 17.9.10, 17.12.8, 17.15.6, 17.18.4 or 17.18.4a, and 26.1.2.
- Cisco says there are no workarounds for the SD-WAN or IOS XE vulnerabilities, so remediation depends on upgrading to fixed software.
The company says it is not aware of public exploitation or malicious use of the vulnerabilities described in either critical advisory. Cisco also notes that the issues were found through internal security testing using existing processes and frontier AI models, making this release a practical example of AI-assisted vulnerability discovery reaching enterprise network products. That detail matters for defenders because the disclosure packages several vulnerability classes at once and puts the operational emphasis on patch planning, supported software branches, and exposure review rather than on a single proof-of-concept flaw.
Sources
Cover photo by panumas nikhomkhai on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment