Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
- ID
- 11700
- Status
- summarized
- Published
- 07 Aug 2026, 1:13 AM
- Fetched
- 07 Aug 2026, 5:39 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 07 Aug 2026, 5:44 PM
- Tags
- Audience
- developers
What happened
Cisco patched 12 vulnerabilities in Catalyst SD-WAN and IOS XE Software, including three CVSS 9.9 bugs (CVE-2026-20303, -20304, -20310) affecting SD-WAN regardless of device configuration. None are known to be actively exploited; Cisco says they were found during internal security testing that included 'frontier AI models.'
Why it matters
Unless your team operates Cisco Catalyst SD-WAN or IOS XE gear in autonomous/controller mode, there is no action to take. The only broadly interesting detail is Cisco's claim that frontier AI models helped surface these bugs — worth noting as a signal of AI-assisted vulnerability discovery becoming routine in enterprise vendor security pipelines, but not something that changes what most builders ship today.
Discussion angle
Does Cisco's use of 'frontier AI models' in internal vuln hunting hint at a near-future where AI-assisted fuzzing finds CVEs in the libraries and frameworks this audience actually ships with — and should that change how teams think about dependency patching cadence?