Cisco has released security updates to fix 12 critical vulnerabilities affecting its Catalyst SD-WAN and IOS XE Software, discovered during an internal security review that included testing with frontier AI models. The networking giant said the flaws were identified through existing testing processes augmented by AI capabilities and are not currently being exploited in the wild. The security issues impact Catalyst SD-WAN Software regardless of how devices are configured, as well as IOS XE Software running in either autonomous or controller mode.
Five vulnerabilities affect the Catalyst SD-WAN platform, with three rated at the maximum severity of 9.9 on the CVSS scale. CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 represent improper input validation, access control, and link resolution flaws, respectively. Two additional bugs—CVE-2026-20312 (scored 8.8) and CVE-2026-20313 (scored 7.7)—involve cleartext storage of sensitive data and improper validation of input quantities. Fixes are available in versions 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, and 26.1.2, with users on versions earlier than 20.9 advised to migrate entirely to a patched release. Seven separate flaws impact IOS XE Software, spanning improper access control, command injection, and input validation weaknesses. The most severe is CVE-2026-20272, rated 9.8, which allows improper neutralization of special elements and covers command, operating system, and argument injection attacks. CVE-2026-20267 scores 9.0 for improper access control, while five others—CVE-2026-20268 through CVE-2026-20273—each score 8.6 and include buffer overflows, out-of-bounds writes, resource lifetime control issues, arithmetic errors, and insufficient control flow management. Patches are available in versions 17.9.10, 17.12.8, 17.15.6, 17.18.4, and 26.1.2.
Cisco also addressed a high-severity flaw in the web-based management interface of its Integrated Management Controller, known as CIMCown, for which a proof-of-concept exploit already exists. CVE-2026-20200, scored 8.8, stems from improper validation of user input and allows an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system and escalate to root access. Security researcher Christoph Peil, who discovered the bug, warned that compromising the IMC is particularly serious because the controller can influence BIOS and SecureBoot and interact with the operating system layer. "An attacker who gains root here can thereby nest themselves deeply and persistently in the system—far below what classic protective measures such as EDR solutions at the operating-system level can even see," Peil stated. A related flaw, CVE-2026-20288 (scored 6.5), requires Admin privileges but enables the same privilege escalation to root.
The disclosure follows Cisco's warning last week about active exploitation of CVE-2026-20316, a separate vulnerability in Secure Firewall Management Center Software that permits low-privilege accounts to access sensitive data within affected systems. The company urged customers to apply all necessary updates for optimal protection, emphasizing the comprehensive nature of the internal security review that uncovered the dozen flaws. The use of frontier AI models in identifying these vulnerabilities marks a notable shift in how enterprise vendors are conducting security audits, potentially enabling faster discovery of complex attack vectors before adversaries can weaponize them. For organizations running affected Catalyst SD-WAN or IOS XE deployments, the simultaneous release of multiple critical patches creates an urgent patching window, particularly given the availability of proof-of-concept code for the IMC vulnerability and the recent pattern of active exploitation against Cisco infrastructure. The discovery process itself may signal a new era in vulnerability detection, though the ultimate test will be whether AI-assisted audits can stay ahead of increasingly sophisticated threat actors who are likely deploying similar capabilities offensively.

