Affected Systems
Cisco Catalyst SD-WAN Software (all versions prior to 20.9, versions 20.9–26.1); Cisco IOS XE Software versions 17.9–26.1 running in autonomous or controller mode; Cisco Integrated Management Controller (IMC) web interface. Affects all SD-WAN devices regardless of configuration.
Exploitation Status
Not actively exploited. Discovered during internal security testing using AI-assisted methods. However, CVE-2026-20200 (IMC vulnerability) has a public proof-of-concept exploit available.
Business Impact
Three vulnerabilities scored 9.8–9.9 enable unauthenticated remote attackers to exploit input validation, access control, and command injection flaws in SD-WAN and IOS XE devices. The IMC vulnerability (CVE-2026-20200, CVSS 8.8) allows low-privilege attackers to gain root access below OS-level detection, compromising BIOS, SecureBoot, and the hardware trust anchor. Organizations running affected Cisco network infrastructure face potential unauthorized access, privilege escalation, and persistent compromise.
Urgency
🟠 Within 24 hours
Recommended Actions
- Upgrade Cisco Catalyst SD-WAN Software to fixed versions: 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, or 26.1.2 depending on current branch
- Upgrade Cisco IOS XE Software to fixed versions: 17.9.10, 17.12.8, 17.15.6, 17.18.4/17.18.4a, or 26.1.2
- Patch Cisco Integrated Management Controller (IMC) immediately to address CVE-2026-20200 due to available PoC exploit
- Audit IMC access logs for unauthorized authentication attempts or privilege escalation activity, focusing on low-privilege accounts
- Review Cisco security advisories for device-specific applicability and monitor for follow-up guidance on CVE-2026-20316 (FMC) active exploitation
