CRITICAL: Cisco Patches Three CVSS 9.9 Catalyst SD-WAN Flaws and Seven IOS XE Bugs
Cisco shipped security hardening releases for Catalyst SD-WAN and IOS XE on August 5, 2026, fixing 12 flaws including three rated CVSS 9.9 and a 9.8 command injection. There are no workarounds and no configuration mitigations, only fixed images, and the low privileges required rating means any authenticated account on SD-WAN Manager is now a critical severity foothold.