nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-20304 CVE-2026-20304
CRITICAL
Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities
Record summary
CVE-2026-20304 has a selected CVSS score of 9.9 (critical).
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Cisco Catalyst SD-WAN ControllerBrowse Cisco / Cisco Catalyst SD-WAN ControllerDefault status: unknown | CVE List | 20.6.4 | affected |
| 20.9.2 | affected | ||
| 20.3.6 | affected | ||
| 20.7.2 | affected | ||
| 20.7.1 | affected | ||
| 20.5.1 | affected | ||
| 20.6.2 | affected | ||
| 19.3.0 | affected | ||
| 20.6.1 | affected | ||
| 17.2.4 | affected | ||
| 18.2.0 | affected | ||
| 18.4.6 | affected | ||
| Showing 12 of 147 version ranges | |||
Cisco Catalyst SD-WAN ManagerBrowse Cisco / Cisco Catalyst SD-WAN ManagerDefault status: unknown | CVE List | 20.1.12 | affected |
| 19.2.1 | affected | ||
| 18.4.4 | affected | ||
| 18.4.5 | affected | ||
| 20.1.1.1 | affected | ||
| 20.1.1 | affected | ||
| 19.3.0 | affected | ||
| 19.2.2 | affected | ||
| 19.2.099 | affected | ||
| 18.3.6 | affected | ||
| 18.3.7 | affected | ||
| 19.2.0 | affected | ||
| Showing 12 of 393 version ranges | |||
References
2cisco-sa-hardening-sdwan-faLcR3K
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K