CVE detail
CVE-2026-20312
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 3
- highest bucket
Evidence
Source links by recency
5 source links · newest first
the necessary updates for optimal protection. The vulnerabilities impacting Catalyst SD-WAN Software are listed below - CVE-2026-20303 (CVSS score: 9.9) - An improper input validation vulnerability (which also covers path traversals) CVE-2026-20304 (CVSS score: 9.9) - An improper access control vulnerability CVE-2026-20310 (CVSS score: 9.9) - An improp
newsthehackernews.comAug 6, 2026, 5:13 PMthe CVEs were assigned to multiple weaknesses grouped by the underlying vulnerability class. Three of the CVEs, namely CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, have a CVSS score of 9.9 and are described as improper input validation, improper access control, and improper link resolution before file access. The remaining two, CVE-2026-20312 a
newswww.securityweek.comAug 6, 2026, 7:20 AM- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3Ksec.cloudapps.cisco.com
No excerpt available.
Vendor Advisorysec.cloudapps.cisco.comAug 5, 2026, 5:16 PM - Cisco Advance Notification for Publication of August 5, 2026, Security AdvisoriesCisco Security Advisories
ry CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20312 CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-
vendorsec.cloudapps.cisco.comAug 5, 2026, 4:01 PM - Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026Cisco Security Advisories
om/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K Security Impact Rating: Critical CVE: CVE-2026-20303,CVE-2026-20304,CVE-2026-20310,CVE-2026-20312,CVE-2026-20313
vendorsec.cloudapps.cisco.comAug 5, 2026, 4:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-55997CVSS 8.8 · High
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration,…
- CVE-2026-15721CVSS 9.8 · Critical
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affe…
- CVE-2026-18591CVSS 0.9 · Low
A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supp…
- CVE-2026-34490CVSS 4.8 · Medium
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retr…
- CVE-2026-59327CVSS 4.4 · Medium
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch conf…
- CVE-2026-55985CVSS 5.3 · Medium
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated…