Skip to main content

Cisco August 2026 Security Bundle Patches Critical IOS XE and SD-WAN Vulnerabilities (CVE-2026-20303 and Others)

Scope: Cisco Catalyst SD-WAN Software, Cisco IOS XE Software, Cisco IOS Software, Cisco Integrated Management Controller

Severity:  Red

Cisco released its August 5, 2026 security bundle addressing 15 vulnerabilities across its core networking infrastructure products, with the most severe being a cluster of five Critical flaws (CVSS 9.9) in Cisco Catalyst SD-WAN Software and seven Critical flaws (CVSS 9.8) in Cisco IOS XE Software. The SD-WAN cluster (CVE-2026-20303 through CVE-2026-20313) represents Cisco's ninth SD-WAN security hardening release of 2026, reflecting sustained attacker pressure on this product line following confirmed exploitation of CVE-2026-20182 and CVE-2026-20245 earlier this year. The IOS XE cluster addresses command injection, privilege escalation, and authentication bypass conditions across routers and switches that form the backbone of enterprise and government network infrastructure across Uganda and the region. Organizations running Cisco SD-WAN, IOS XE, or IOS should apply the August 2026 hardening release immediately and refer to Cisco's advisory for the specific fixed software versions applicable to their deployment.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.