Cisco is releasing software updates to address multiple security vulnerabilities affecting its Catalyst SD-WAN and IOS XE products. According to reporting from multiple outlets, the fixes cover issues in Cisco Catalyst SD-WAN Software that apply regardless of device configuration. The updates also address vulnerabilities in Cisco IOS XE Software when it is operating in autonomous mode or controller mode.
One outlet reports that Cisco patches a wide set of flaws—described as totaling around two dozen or 12, depending on how each source groups or counts the underlying issues. The updates include at least one vulnerability for which public proof-of-concept (PoC) code is available. Another report highlights that among the patched weaknesses are bugs with high severity, including vulnerabilities scored at 9.8 (CVSS), indicating serious potential impact.
The disclosures describe the vulnerabilities as being identified through Cisco’s internal security review process. Cisco provides patch guidance through its security advisories and release notes, directing customers to update affected components to remediate the reported weaknesses.