← Blog · · df00tech

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three Critical (CVSS 9.8) Bugs

security-news advisory

What happened

Cisco has released patches for 12 security vulnerabilities affecting Catalyst SD-WAN Software and IOS XE Software, discovered as part of an internal security review, according to The Hacker News. Three of the flaws carry a maximum-severity CVSS score of 9.8. The Catalyst SD-WAN issues affect the software regardless of device configuration, while the IOS XE issues apply when the software is running in autonomous or controller mode.

Why it matters

Cisco Catalyst SD-WAN and IOS XE run on core routing and WAN infrastructure across enterprise and service-provider networks. A 9.8 CVSS score typically implies remote, low-complexity exploitation with significant impact to confidentiality, integrity, or availability — the kind of rating usually reserved for unauthenticated remote code execution or authentication bypass. Given SD-WAN's role as a network edge and control-plane component, successful exploitation could expose branch and site-to-site traffic or provide a foothold into the broader WAN.

The source item does not yet detail the specific vulnerability classes, attack vectors, or whether any of the 12 flaws are known to be exploited in the wild — those details should be confirmed against Cisco's own advisories before drawing further conclusions.

What defenders should do now

  • Inventory all Catalyst SD-WAN and IOS XE devices (including controller-mode instances) and prioritize patching, especially anything internet-facing or reachable from untrusted segments.
  • Review Cisco's official security advisories for the specific CVE IDs, affected versions, and exploitability assessments once published, and cross-reference against your fleet.
  • Restrict management-plane access (HTTP/HTTPS UI, NETCONF/RESTCONF, SSH) to trusted management networks as a general hardening step while patches are rolled out.
  • Monitor device logs and network telemetry for unexpected configuration changes, unauthorized admin sessions, or anomalous traffic to/from SD-WAN control components.
  • Where available, enable Cisco's advisory notification feeds to catch any updates indicating active exploitation.

Developing story

This is net-new intelligence and details are still emerging — Cisco's individual advisories will contain the authoritative CVE identifiers, affected versions, and remediation guidance. Read the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.