CVE-2026-20304: Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20304?
CVE-2026-20304 has a severity rating of critical with a score of 9.9.
How do I fix CVE-2026-20304?
To fix CVE-2026-20304, users should apply the software hardening release provided by Cisco for the Catalyst SD-WAN.
What types of vulnerabilities does CVE-2026-20304 address?
CVE-2026-20304 addresses access control vulnerabilities in Cisco Catalyst SD-WAN.
Is CVE-2026-20304 applicable to all Cisco products?
CVE-2026-20304 specifically impacts the Cisco Catalyst SD-WAN product line.
When was CVE-2026-20304 published?
CVE-2026-20304 was published on August 5, 2026.