Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-20304: Cisco Catalyst SD-WAN Access Control Flaw Exposes Network

CVE-2026-20304 CVE-2026-20304
Summary

Cisco Catalyst SD-WAN software has an access control issue that could allow unauthorized users to access sensitive parts of the network. This is a security concern because it could lead to unauthorized changes or data theft. To fix this issue, Cisco has released a software update that addresses the problem.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
cisco cisco catalyst sd-wan controller 20.6.4
cisco cisco catalyst sd-wan manager 20.1.12
Original title
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resul...
Original description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
mitre CVSS3.1 9.9
Vulnerability type
CWE-284 Improper Access Control
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026