Access Control Vulnerabilities in Cisco Catalyst SD-WAN
CVE-2026-20304
9.9CRITICAL
What is CVE-2026-20304?
Cisco Catalyst SD-WAN is affected by improper access control issues, which could potentially allow unauthorized access to system resources. The vulnerabilities have been identified as part of a proactive security review by Cisco, leading to a software hardening release aimed at mitigating these risks. Organizations utilizing the Cisco Catalyst SD-WAN should review their deployments and apply the necessary updates to enhance their security posture.
Affected Version(s)
Cisco Catalyst SD-WAN Controller 20.6.4
Cisco Catalyst SD-WAN Controller 20.9.2
Cisco Catalyst SD-WAN Controller 20.3.6