SOFTWARE ADVISORY NOTICE

Dear Cisco Customer,

This Release is impacted by one or more of the following security vulnerabilities described in the Cisco Software Advisories:

CVE-2026-20122
CVE-2026-20126
CVE-2026-20128
CVE-2026-20127


Link to vulnerability advisory: 
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Vulnerabilities

Cisco advises customers to use or upgrade to one of the latest SW versions with the fixes. Following are the latest fixed SW recommendations for each active release train:

All releases 20.16.x through 20.18.x will be deferred to 20.18.2.1 or later.
All releases 20.13.x through 20.15.x will be deferred to 20.15.4.2 or later.
All releases 20.10.x through 20.12.x will be deferred to 20.12.5.3, 20.12.6.1 or later.
All releases 20.3.x through 20.9.x will be deferred to 20.9.8.2 or later.


Disclaimer:

This Software Advisory announces the introduction of replacement image that increases network performance. Cisco will discontinue manufacturing shipments of the affected images. Cisco recommends that you upgrade to the replacement image, should there be any need to replace the affected images. Any pending or future orders will be automatically substituted by the replacement software images.

The terms and conditions that governed your rights and obligations and those of Cisco, with respect to the original image will apply to the replacement image.