Skip to main content

CVE detail

CVE-2026-20312

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.

CVSS 8.8 · HighBuzz score 34.4

Buzz score

Why this CVE is surfacing

Buzz score total 34.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 17.9 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
17.9
5 evidence mentions in the snapshot
Diversity score
16.5
4 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
5
within the 30d window
Peak daily
3
highest bucket

Evidence

Source links by recency

Newest mentions first
5 source links · newest first
  • the necessary updates for optimal protection. The vulnerabilities impacting Catalyst SD-WAN Software are listed below - CVE-2026-20303 (CVSS score: 9.9) - An improper input validation vulnerability (which also covers path traversals) CVE-2026-20304 (CVSS score: 9.9) - An improper access control vulnerability CVE-2026-20310 (CVSS score: 9.9) - An improp

    newsthehackernews.comAug 6, 2026, 5:13 PM
  • the CVEs were assigned to multiple weaknesses grouped by the underlying vulnerability class. Three of the CVEs, namely CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, have a CVSS score of 9.9 and are described as improper input validation, improper access control, and improper link resolution before file access. The remaining two, CVE-2026-20312 a

    newswww.securityweek.comAug 6, 2026, 7:20 AM
  • No excerpt available.

    Vendor Advisorysec.cloudapps.cisco.comAug 5, 2026, 5:16 PM
  • ry CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20312 CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-

    vendorsec.cloudapps.cisco.comAug 5, 2026, 4:01 PM
  • Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026Cisco Security Advisories

    om/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K Security Impact Rating: Critical CVE: CVE-2026-20303,CVE-2026-20304,CVE-2026-20310,CVE-2026-20312,CVE-2026-20313

    vendorsec.cloudapps.cisco.comAug 5, 2026, 4:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-55997

    Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration,…

    CVSS 8.8 · High
    2 mentions
  • CVE-2026-15721

    Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affe…

    CVSS 9.8 · Critical
    1 mention
  • CVE-2026-18591

    A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supp…

    CVSS 0.9 · Low
    6 mentions
  • CVE-2026-34490

    Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retr…

    CVSS 4.8 · Medium
    2 mentions
  • CVE-2026-59327

    Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch conf…

    CVSS 4.4 · Medium
    1 mention
  • CVE-2026-55985

    The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated…

    CVSS 5.3 · Medium
    3 mentions