🔴 Critical | Source: The Hacker News
Cisco has released patches addressing 12 security vulnerabilities across its Catalyst SD-WAN and IOS XE Software, including three rated 9.8 out of 10 on the CVSS severity scale — the highest possible for exploitability. These flaws affect a wide range of Cisco networking infrastructure regardless of device configuration, meaning the attack surface is broad. Unpatched devices could allow remote attackers to take full control of affected systems without requiring authentication.
Security Architect’s Take: Prioritise patching immediately, particularly for any internet-facing Cisco IOS XE or Catalyst SD-WAN devices — the three CVSS 9.8 vulnerabilities should be treated as critical regardless of current threat intelligence. Audit your SD-WAN estate for affected software versions and apply Cisco’s published fixed releases; consider temporarily restricting management-plane access to trusted IP ranges as a compensating control whilst patching is scheduled.
Original advisory: Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs