CVE-2026-20304
CRITICAL · CVSS 9.9 · EPSS 0.25% · CWE CWE-284
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
CVE-2026-20304 is confirmed by Cisco as affecting 2 products, including Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, via 1 advisory (CVSS 9.9; EPSS 0.3%).
2 products with CSAF evidence