CVE-2026-20303
CRITICAL · CVSS 9.9 · EPSS 0.29% · CWE CWE-20
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.
CVE-2026-20303 is confirmed by Cisco as affecting 2 products, including Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, via 1 advisory (CVSS 9.9; EPSS 0.3%).
2 products with CSAF evidence