Multiple Vulnerabilities in Cisco IOS XE Software
7 August 2026
Multiple vulnerabilities have been identified in Cisco IOS XE Software that could allow attackers to execute arbitrary commands, bypass security controls, gain unauthorised access, disclose sensitive information, or affect the operation of vulnerable systems. Patch immediately.
Background
Cisco has released security updates to address multiple vulnerabilities (CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20272, & CVE-2026-20273) affecting Cisco IOS XE Software.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-20267 (CVSS 9.0): Improper access control that could potentially allow authentication or authorisation bypass.
CVE-2026-20268 (CVSS 8.6): Memory buffer handling issues that could potentially lead to memory corruption.
CVE-2026-20269 (CVSS 8.6): Improper resource lifetime management that could potentially result in memory or resource handling issue.
CVE-2026-20270 (CVSS 8.6): Incorrect calculation errors, including numeric conversion or integer handling issues.
CVE-2026-20271 (CVSS 8.6): Insufficient control-flow management that could potentially result in race conditions or infinite loops.
CVE-2026-20272 (CVSS 9.8): Improper neutralisation of special elements that could potentially enable command injection.
CVE-2026-20273 (CVSS 8.6): Improper input validation that could potentially allow path traversal or unsafe path handling.
Affected Products
The vulnerabilities affect Cisco IOS XE Software running in autonomous or controller mode, including the following release trains:
Cisco IOS XE Software Release 17.9
Cisco IOS XE Software Release 17.12
Cisco IOS XE Software Release 17.15
Cisco IOS XE Software Release 17.18
Cisco IOS XE Software Release 26.1
Recommendations
Users and administrators of affected products are advised to update to the latest fixed software releases immediately.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-20267
https://nvd.nist.gov/vuln/detail/CVE-2026-20268
https://nvd.nist.gov/vuln/detail/CVE-2026-20269
https://nvd.nist.gov/vuln/detail/CVE-2026-20270
https://nvd.nist.gov/vuln/detail/CVE-2026-20271
