Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.
Published: 2026-08-05
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw results from improper input validation, classified under CWE-20. The vulnerability could allow an attacker with crafted input to influence the behavior of the Cisco Catalyst SD‑WAN Controller or Manager. The advisory does not describe the specific exploitation mechanism; however, the high CVSS score of 9.9 indicates a severe risk. Based on the score, it is inferred that the issue could potentially enable significant compromise of system functionality or data availability.

Affected Systems

This vulnerability affects Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager appliances. No specific firmware or software versions are identified in the advisory, so all existing deployments of these products should be considered vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 9.9 marks this issue as critical, and the lack of an EPSS score means the official probability of exploitation is not quantified. The advisory does not list the vulnerability in CISA’s KEV catalog. The advisory does not detail the attack vector. However, given typical exploitation of input‑validation vulnerabilities and the remote nature of SD‑WAN management interfaces, it is inferred that a remote attacker could potentially target exposed APIs or interfaces. No specific privileges beyond access to management interfaces appear required, so environments with unrestricted network access remain at elevated risk.

Generated by OpenCVE AI on August 5, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all Cisco Catalyst SD‑WAN Controller and Manager instances to the latest hardening release containing the input‑validation fix
  • Restrict or segment network access to the SD‑WAN Controller and Manager so that only trusted management hosts can reach them
  • Enforce strict input validation on all externally exposed endpoints, rejecting malformed or out‑of‑range data before processing
  • Enable and review logs for suspicious input handling failures to detect potential exploitation attempts

Generated by OpenCVE AI on August 5, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 21:30:00 +0000


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller
Vendors & Products Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.
Title Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Catalyst Sd-wan Manager Cisco Catalyst Sd-wan Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-14T21:00:51.494Z

Reserved: 2025-10-08T11:59:15.408Z

Link: CVE-2026-20303

cve-icon Vulnrichment

Updated: 2026-08-14T21:00:51.494Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:50.513

Modified: 2026-08-14T21:17:15.770

Link: CVE-2026-20303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:52Z

Weaknesses
  • CWE-20

    Improper Input Validation