CVE-2026-20312: Cisco Catalyst SD-WAN Controller

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.

Affected products

  • Cisco Cisco Catalyst SD-WAN Controller: version 20.6.4 only; version 20.9.2 only; version 20.3.6 only; version 20.7.2 only; version 20.7.1 only; version 20.5.1 only; …
  • Cisco Cisco Catalyst SD-WAN Manager: version 20.1.12 only; version 19.2.1 only; version 18.4.4 only; version 18.4.5 only; version 20.1.1.1 only; version 20.1.1 only; …

Published 2026-08-05. Last modified 2026-08-14.