Cisco Ships Wide Fixes Across Control-Plane Products

Cisco’s latest patch cycle matters because it reaches the management and routing systems that can hand an attacker broad control, not just isolated appliances. The old IOS XE workaround is no longer the main story; operators now have multiple Cisco surfaces to patch across Catalyst SD-WAN, IOS XE, and FMC. Among the fixes are CVE-2026-20079 in Secure Firewall Management Center, a CVSS 10 authentication bypass that lets an unauthenticated attacker send crafted HTTP requests and run scripts as root. Cisco also shipped seven IOS XE fixes, including CVE-2026-20272, a critical command injection issue, plus five Catalyst SD-WAN fixes tied to input validation, access control, link resolution, cleartext storage, and input quantity checks. Cisco says it is not aware of in-the-wild exploitation, but the presence of critical flaws across control-plane products raises the chance that one weak point could be used to move deeper into network administration.

Part of the PlainSec briefing for 2026-08-06

Editions

Sources