SINGAPORE, 7 AUG 2026 — Singapore's Cyber Security Agency issued two Cisco alerts on 7 August, covering twelve vulnerabilities across Catalyst SD-WAN and IOS XE. Three of them score 9.9 and one scores 9.8.
We read every alert CSA has published since 2020 to see how unusual that is. Cisco is the vendor it warns about more than any other, and 2026 is already the heaviest Cisco year on record with nearly five months still to run.
What was issued
The Catalyst SD-WAN alert covers five vulnerabilities. Three are rated 9.9: an improper input validation flaw reaching path traversal or external path control, an improper access control flaw allowing authentication or authorisation bypass, and an improper link resolution flaw allowing files to be accessed improperly. A cleartext storage flaw at 8.8 and an input validation flaw at 7.7 complete the set. The affected software is Catalyst SD-WAN releases earlier than 20.9.
The IOS XE alert covers seven, affecting software running in autonomous or controller mode. The highest is 9.8, an improper neutralisation of special elements enabling command injection. An improper access control flaw sits at 9.0 and the remaining five at 8.6, spanning memory corruption, resource lifetime handling, integer handling, control-flow management and path traversal.
Neither alert reports active exploitation. Both carry the same instruction: patch immediately.
What the record shows
CSA publishes each alert and advisory at a stable URL with a sequential code. We took all 847 of them, from 2020 through 7 August 2026, and counted.
| Year | All CSA alerts and advisories | Naming Cisco |
|---|---|---|
| 2020 | 58 | 4 |
| 2021 | 81 | 1 |
| 2022 | 95 | 4 |
| 2023 | 191 | 12 |
| 2024 | 168 | 6 |
| 2025 | 145 | 11 |
| 2026 to 7 Aug | 109 | 13 |
RECATOOLS count of all 847 coded CSA alerts and advisories listed in the agency's sitemap, each fetched for its title and publication date; 847 fetched, 847 titles retrieved, no errors. The Cisco column counts titles naming Cisco, which will undercount any alert that covers Cisco products without naming the vendor in its title.
Thirteen Cisco alerts in a little over seven months is more than any full year in the series. The previous high was twelve, in 2023, a year in which CSA published 191 alerts in total against 109 so far this year.
Across the whole corpus Cisco leads at 51 mentions, ahead of Apple at 36, VMware at 30, Chrome at 27, Microsoft at 25, Apache at 24 and Google at 24.
One product line accounts for most of it
The concentration inside the Cisco figure is sharper than the figure itself.
| Date | Catalyst SD-WAN alert |
|---|---|
| 29 Sep 2023 | Critical Vulnerability Affecting Cisco Catalyst SD-WAN Manager |
| 26 Feb 2026 | Active Exploitation of Critical Vulnerability in Cisco Catalyst SD-WAN |
| 15 May 2026 | Active Exploitation of Critical Vulnerability in Cisco Catalyst SD-WAN |
| 16 Jun 2026 | Vulnerability in Cisco Catalyst SD-WAN Manager |
| 7 Aug 2026 | Multiple Vulnerabilities in Cisco Catalyst SD-WAN Software |
Every CSA alert naming Catalyst SD-WAN, 2020 to 7 August 2026, from the same 847-record extraction. Titles are reproduced as CSA published them.
CSA has issued five alerts naming Catalyst SD-WAN in seven years. Four of them are from 2026, and two of those four report active exploitation rather than a patch advisory.
One alert for a product line in six years, then four in seven months, suggests something more specific than a vendor just shipping more fixes.
What an SD-WAN controller is, and why the number matters
SD-WAN software runs the control plane for a wide-area network. It decides which links carry which traffic between sites, holds the policy that governs those decisions, and in the manager component holds administrative reach into the devices at every branch.
This context changes how the severity scores should be read. An authentication bypass on a system that administers a network estate grants a position above all the machines, not just a foothold on one.
It is also why the pairing in the record is worth reading carefully. Two of the four alerts this year were not warnings that a fix exists. They were notifications that somebody was already through.
The rest of the ranking
Cisco leads the corpus, but the shape of the list underneath it says something too.
| Vendor or product named in the title | Alerts, 2020 to 7 Aug 2026 |
|---|---|
| Cisco | 51 |
| Apple | 36 |
| VMware | 30 |
| Chrome | 27 |
| Microsoft | 25 |
| Apache | 24 |
| 24 | |
| Ivanti | 22 |
| WordPress | 21 |
| Fortinet | 20 |
RECATOOLS count of title matches across the same 847-record corpus. Chrome and Google are counted separately because CSA titles them separately, so a Chrome alert may also match Google; the two columns are not additive.
The list is heavily weighted toward network and virtualisation infrastructure. Cisco, VMware, Ivanti and Fortinet occupy four of the top ten spots, a focus on plumbing you would not see in a consumer-facing threat feed. And WordPress at twenty-one is the only entry aimed squarely at small organisations, which says something about who else CSA is writing for.
The corpus also splits by document type. Of the 847 records, 744 are alerts and 103 are advisories, the latter being the longer-form documents CSA issues when a situation needs more than a patch instruction.
What this does not show
An alert count measures publication, not insecurity.
A vendor with a mature disclosure programme generates more advisories than one that quietly fixes things, and more advisories generate more alerts. Cisco is large, its products are widely deployed in exactly the enterprise and government estates CSA exists to protect, and both facts would raise its count without anything having got worse.
Our method has its own limits. We counted titles naming the vendor, so an alert covering Cisco products without naming Cisco in the title is not counted. The corpus is what CSA publishes at coded URLs and excludes twenty-five older items with descriptive slugs. And an alert is one document regardless of whether it carries one vulnerability or twelve, so a count of alerts is not a count of flaws.
The caveats do not change the comparison against CSA's own history. The agency is on pace for roughly 182 alerts this year against a 191 peak in 2023, so total output is high but not unprecedented. The Cisco share of it is.
The release trains involved
The IOS XE alert names five release trains: 17.9, 17.12, 17.15, 17.18 and 26.1. The spread covers both long-lived maintenance branches and current numbering, so standardising on an older train offers no protection.
On the SD-WAN side the affected range is anything earlier than release 20.9, stated as a single threshold rather than a list.
What to do about the two alerts
The mechanical answer is CSA's: patch immediately, from the vendor's advisory rather than from a summary.
The real judgement call is how to order the work. Twelve vulnerabilities across two alerts will not all be remediated in one window, and the scores are not the only guide. An internet-reachable controller carrying a 9.9 authentication bypass is a different proposition from an 8.6 memory-handling flaw on a device inside a management VLAN, even though both appear on the same page on the same day.
Given this year's record, check whether the SD-WAN management interface is reachable from anywhere it should not be. That is the surface the two active-exploitation alerts this year concerned, and it is the one that turns a patch backlog into an incident.
Why a count is still worth keeping
None of the caveats above makes the exercise pointless, and it is worth saying why.
A national CERT's alert history is a record of what one well-resourced institution judged its constituency needed warning about, published continuously for seven years under a stable format. That is rare. Most threat data is either vendor marketing or proprietary, and neither is auditable by a reader.
Counting it will not tell you which product is least secure. It will tell you where a regional defender's attention has been directed, and that is a different question with its own value.
What to watch
Two things.
The first is whether either of today's alerts is followed by an active-exploitation notice. That has happened twice this year on this product line, and the interval between a patch alert and an exploitation alert is the window defenders actually get.
The second is whether the Cisco count keeps climbing. Thirteen with nearly five months to run could settle at a normal year if the rate falls, or reach twenty if it does not. The second outcome would be a break in a seven-year series, not just a busy patch cycle.