TL;DR
Cisco patched seven Cisco IOS XE vulnerability issues in an August 2026 hardening release. Two are Critical, led by CVE-2026-20272 at CVSS 9.8. Cisco found them internally and reports no active exploitation.
- Total: 7 CVEs
- Severity: 2 Critical · 5 High
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-20272
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-20272 | 9.8 | CWE-74 | — | Not exploited |
| CVE-2026-20267 | 9 | CWE-284 | — | Not exploited |
| CVE-2026-20268 | 8.6 | CWE-119 | — | Not exploited |
| CVE-2026-20269 | 8.6 | CWE-664 | — | Not exploited |
| CVE-2026-20270 | 8.6 | CWE-682 | — | Not exploited |
| CVE-2026-20271 | 8.6 | CWE-691 | — | Not exploited |
| CVE-2026-20273 | 8.6 | CWE-20 | — | Not exploited |
Why This Cisco IOS XE Vulnerability Matters
IOS XE powers a huge range of Cisco routers and switches. Therefore, a flaw here reaches deep into enterprise and carrier networks. The bugs affect the software in both autonomous and controller mode, regardless of configuration.
According to the official Cisco security advisory, the review covered releases 17.9, 17.12, 17.15, 17.18, and 26.1.
How the Attacks Work
Cisco grouped the flaws by weakness class and gave each one a CVE. Two rank as Critical.
CVE-2026-20272: Command Injection
This bug, scoring 9.8, stems from improper neutralization of special elements. As a result, it opens the door to command, OS, and argument injection.
CVE-2026-20267: Access Control
This flaw scores 9.0. It breaks authorization and authentication, so attackers may bypass privilege checks.
The High-Severity Flaws
Five more bugs each score 8.6. They cover buffer overflows, resource lifetime errors, incorrect calculations, control-flow gaps, and input validation.
Affected Versions
The flaws affect IOS XE releases 17.9 through 26.1. Cisco confirms no known exploitation in the wild and no public proof-of-concept. Notably, Catalyst 3650 and 3850 switches were not part of this review.
Patch and Mitigation Steps
There are no workarounds, so patching is the only fix. Upgrade to a fixed release right away:
- 17.9: upgrade to 17.9.10
- 17.12: upgrade to 17.12.8
- 17.15: upgrade to 17.15.6
- 17.18: upgrade to 17.18.4 or 17.18.4a
- 26.1: upgrade to 26.1.2
Customers on older releases should migrate to a supported, fixed build.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.