NCSC-2026-0277 [1.00] [M/H] Vulnerabilities patched in Cisco Catalyst SD-WAN
Cisco has patched multiple vulnerabilities in Cisco Catalyst SD-WAN. The identified issues include improper input validation, improper access control, improper link resolution prior to file access, and storage of sensitive information in cleartext. Through these vulnerabilities, the software may potentially exhibit unintended behavior when processing input, controlling access rights, opening files, and protecting sensitive data.
CSIRTS triage
- What
- Multiple vulnerabilities including improper input validation, access control bypass, insecure link resolution, and cleartext sensitive data storage in Catalyst SD-WAN.
- Who is affected
- Deployments of Cisco Catalyst SD-WAN with unpatched versions.
- Urgency
- Medium to high urgency; Cisco has released patches and these could enable unauthorized access or data exposure.
- Action
- Upgrade to patched Catalyst SD-WAN versions per Cisco advisory NCSC-2026-0277.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Catalyst SD-WAN
Get an email when a new Catalyst SD-WAN advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0277
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-203030.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203040.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203100.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203120.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203130.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20303 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20304 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20310 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20312 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20313 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Cisco Catalyst SD-WAN Manager: Multiple Vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Cisco products (August 6, 2026)cert-fr-avis
- highCVE-2026-20313: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd
- highCVE-2026-20312: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd
- criticalCVE-2026-20310: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd
- criticalCVE-2026-20304: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd
- criticalCVE-2026-20303: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd
- criticalCisco Advance Notification for Publication of August 5, 2026, Security Advisoriescisco-psirt
- criticalCisco Catalyst SD-WAN Software Security Hardening Release: August 2026cisco-psirt
Recent advisories for Cisco Catalyst SD-WAN
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Cisco Catalyst SD-WAN Manager: Multiple Vulnerabilitiescert-bund · 2026-08-06
- highCVE-2026-20313: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- highCVE-2026-20312: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- criticalCVE-2026-20310: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- criticalCVE-2026-20304: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
- criticalCVE-2026-20303: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cat…nvd · 2026-08-05
More from NCSC-NL Advisories
- unknownNCSC-2026-0275 [1.01] [M/H] Vulnerabilities patched in N-able N-central2026-08-07
- unknownNCSC-2026-0278 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic2026-08-06
- unknownNCSC-2026-0276 [1.00] [M/H] Vulnerabilities patched in Veeam Service Provider Console2026-08-05
- unknownNCSC-2026-0268 [1.01] [M/H] Vulnerability patched in SQLite by SQLite Consortium (withdrawn)2026-08-03
- unknownNCSC-2026-0275 [1.00] [M/H] Vulnerabilities patched in N-able N-central2026-08-03