DIRAS TAKE
Treat this as high urgency: public exploit code is available, so exposed controllers should be isolated or access restricted immediately while applying vendor guidance.
What is CVE-2026-20303?
An attacker with network access and a low-privilege account can trigger remote code execution against Cisco Catalyst SD-WAN Controller (CVE-2026-20303) by exploiting improper input validation (CWE-20). Affected releases span multiple 17.x, 19.x and 20.x builds, including 17.2.4, 19.3.0, 20.3.6, 20.5.1, 20.6.1, 20.6.2, 20.6.4, 20.7.1, 20.7.2 and 20.9.2; no fixed release is listed in the supplied facts. The flaw requires network access and low privileges but no user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Which versions of Cisco Cisco Catalyst SD-WAN Controller are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Cisco Catalyst SD-WAN Controller 20.x | 20.6.4 | |
| Cisco Catalyst SD-WAN Controller 20.x | 20.9.2 | |
| Cisco Catalyst SD-WAN Controller 20.x | 20.3.6 | |
| Cisco Catalyst SD-WAN Controller 20.x | 20.7.2 | |
| Cisco Catalyst SD-WAN Controller 20.x | 20.7.1 | |
| Cisco Catalyst SD-WAN Controller 20.x | 20.5.1 | |
| Cisco Catalyst SD-WAN Controller 20.x | 20.6.2 | |
| Cisco Catalyst SD-WAN Controller 19.x | 19.3.0 | |
| Cisco Catalyst SD-WAN Controller 20.x | 20.6.1 | |
| Cisco Catalyst SD-WAN Controller 17.x | 17.2.4 |
Is CVE-2026-20303 being exploited?
Public exploit code is available.
How to fix CVE-2026-20303
- Follow Cisco's official mitigation guidance and advisories for the SD-WAN Controller.
- Restrict network access to the controller to trusted management networks and VPNs; block internet access where possible.
- Harden and rotate low-privilege accounts and credentials; disable or remove unnecessary accounts and services.
- Increase logging and monitor controller authentication and command execution for anomalous activity.
Frequently asked questions
Is CVE-2026-20303 being actively exploited?
Public exploit code is available for CVE-2026-20303, indicating a higher risk of active exploitation.
Which Cisco Catalyst SD-WAN Controller versions are affected by CVE-2026-20303?
Multiple 17.x, 19.x and 20.x releases are listed as affected, including 17.2.4, 19.3.0 and several 20.x builds such as 20.6.4 and 20.9.2.
Is there a patch for CVE-2026-20303?
No fixed release is listed in the provided facts; apply mitigations from Cisco and restrict access until a patched release is published.
Does CVE-2026-20303 require authentication?
Yes; the vulnerability requires a low-privilege authenticated account and network access to the Cisco Catalyst SD-WAN Controller.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20303
- cve.org/CVERecord?id=CVE-2026-20303
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026