Overview
- Cisco released a batch of security updates this week and automatically patched its managed SD‑WAN cloud instances while urging customers to upgrade affected on‑prem IOS XE, Catalyst SD‑WAN, FMC, and IMC releases.
- Secure Firewall Management Center was fixed for CVE‑2026‑20079, a CVSS 10 authentication‑bypass that can let unauthenticated remote actors run scripts and obtain root on affected devices.
- Integrated Management Controller vulnerability CVE‑2026‑20200 allows an authenticated low‑privilege user to execute commands as root and a public proof‑of‑concept called CIMCown was posted after Cisco’s advisory.
- Cisco grouped about two dozen bugs by weakness class across SD‑WAN and IOS XE, with several CVEs scored 9.8–9.9 and many of the networking issues found through internal testing assisted by frontier AI models.
- Researchers and Cisco warn there are no practical workarounds for the IMC flaw beyond updating or disabling the web UI and isolating management networks because IMC can alter BIOS and SecureBoot, making compromises deeply persistent and hard to detect.