
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20310 is a critical improper link resolution before file access (CWE-59) vulnerability affecting Cisco Catalyst SD-WAN Controller and SD-WAN Manager software. Discovered through Cisco's internal security review (including frontier AI-assisted testing), it was publicly disclosed on August 5, 2026. The vulnerability affects a broad range of software versions spanning releases 17.x through 26.x across both the Controller and Manager components, covering all deployment types (on-premises, Cloud-Pro, Cloud Managed, and FedRAMP). It carries a CVSS v3.1 base score of 9.1 (Critical) (Cisco Advisory, GitHub Advisory).
The vulnerability is classified under CWE-59 (Improper Link Resolution Before File Access, also known as 'Link Following'), meaning the affected software fails to properly validate or restrict symbolic link or hard link targets before performing file operations. An authenticated attacker with high-level network privileges can craft symlinks or hard links that redirect file access operations to unintended resources, potentially outside the intended directory scope. Attack patterns associated with this vulnerability include symlink attacks (CAPEC-132), using malicious files (CAPEC-17), and manipulating web input to file system calls (CAPEC-76). The vulnerability requires no user interaction and has a changed scope, meaning successful exploitation can impact resources beyond the vulnerable component itself (Cisco Advisory, GitHub Advisory).
Successful exploitation allows an authenticated attacker with high privileges to read, modify, or delete sensitive files and potentially execute arbitrary code with elevated permissions on the affected SD-WAN Controller or Manager. The changed scope means the impact extends beyond the directly vulnerable component, potentially compromising the entire SD-WAN infrastructure including configuration data, credentials, and network routing policies. Given the central role of SD-WAN controllers and managers in enterprise network orchestration, compromise could enable lateral movement across the managed WAN environment and expose sensitive network topology and credential information (Cisco Advisory, Feedly).
As of the disclosure date, Cisco PSIRT is not aware of any public proof-of-concept exploit code or active malicious exploitation of this vulnerability in the wild (Cisco Advisory). The NVD SSVC assessment indicates exploitation is 'none' and the attack is not automatable. The EPSS score is approximately 0.37–0.39%, placing it in the 32nd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Qualys (ID 317869) and Nessus (ID 333337) (GitHub Advisory).
/etc/, /root/) with timestamps correlating to SD-WAN process activity.Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Customers should upgrade to the following fixed releases: SD-WAN 20.9 → 20.9.10; SD-WAN 20.12 (and 20.10, 20.11) → 20.12.8.1; SD-WAN 20.15 (and 20.13, 20.14) → 20.15.6; SD-WAN 20.18 (and 20.16) → 20.18.4; SD-WAN 26.1 → 26.1.2. Releases earlier than 20.9 have reached End of Software Maintenance and customers must migrate to a supported release. As interim hardening measures, restrict administrative access to SD-WAN management interfaces to only trusted personnel and networks, and monitor file system activity on SD-WAN controllers and managers for suspicious symlink or hard link creation (Cisco Advisory).
Cisco's advisory was widely covered by security media outlets including The Hacker News, SecurityWeek, GBHackers, CyberSecurityNews, and SOCRadar, with coverage noting the breadth of affected versions and the critical severity of the SD-WAN hardening release bundle (The Hacker News, SecurityWeek). Qualys published a threat protection bulletin specifically covering CVE-2026-20310 alongside related SD-WAN CVEs. CISA included the advisory in its weekly bulletin (SB26-222), and government CERTs including AUSCERT and Singapore's CSA issued alerts. Community sentiment highlighted the unusually large number of affected version strings and the use of AI-assisted internal testing as a notable aspect of Cisco's disclosure (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."