Record summary

CVE-2026-20312 has a selected CVSS score of 8.8 (high).

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Cisco Catalyst SD-WAN Controller

Browse Cisco / Cisco Catalyst SD-WAN Controller

Default status: unknown

CVE List20.6.4affected
20.9.2affected
20.3.6affected
20.7.2affected
20.7.1affected
20.5.1affected
20.6.2affected
19.3.0affected
20.6.1affected
17.2.4affected
18.2.0affected
18.4.6affected
Showing 12 of 122 version ranges

Default status: unknown

CVE List20.1.12affected
19.2.1affected
18.4.4affected
18.4.5affected
20.1.1.1affected
20.1.1affected
19.3.0affected
19.2.2affected
19.2.099affected
18.3.6affected
18.3.7affected
19.2.0affected
Showing 12 of 342 version ranges

References

2