
[CIVN-2026-0397] Multiple Vulnerabilities in Cisco IOS XE Software
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Cisco IOS XE Software
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Cisco IOS XE Software (multiple releases as identified by Cisco Software Checker)
Cisco IOS Software (for the XMCP advisory)
Overview
Multiple vulnerabilities have been identified in Cisco IOS XE Software that could allow an attacker to execute arbitrary code, cause denial of service (DoS), bypass security restrictions, or compromise the confidentiality, integrity, and availability of the affected devices.
Target Audience:
Individuals and organizations using Cisco IOS XE Software and Cisco IOS Software.
Risk Assessment:
High risk of remote code execution, denial of service, security restriction bypass, and compromise of critical network infrastructure.
Impact Assessment:
Potential remote code execution, denial of service, security restriction bypass, and disruption of network operations.
Description
Cisco IOS XE Software is a network operating system used on Cisco enterprise routers, switches, wireless controllers, and other networking devices.
Multiple vulnerabilities have been reported in Cisco IOS XE Software due to Unchecked Input for Loop Condition, Error Handling, Missing Release of Resource after Effective Lifetime, Improper Access Control, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Control of a Resource Through its Lifetime, Incorrect Calculation, Insufficient Control Flow Management, Improper Neutralization of Special Elements in Output Used by a Downstream Component (‘Injection’), and Improper Input Validation.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, cause denial of service (DoS), bypass security restrictions, inject malicious input, access unauthorized resources, or compromise the confidentiality, integrity, and availability of the affected devices.
Solution
Apply appropriate updates as mentioned by the vendor
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/home.x
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t
CVE Name
CVE-2026-20301
CVE-2026-20263
CVE-2026-20124
CVE-2026-20267
CVE-2026-20268
CVE-2026-20269
CVE-2026-20270
CVE-2026-20271
CVE-2026-20272
CVE-2026-20273
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7DBgACgkQ3jCgcSdc
ys9Hgw//fjO6lydIb8idQEbbBboN6XDfVp92v93963TLiEhegpX7anp0TdfnXLF7
X7qNkO6FSIeTlov9eFnlqD3zfVqx7VtjzYb7hC/PexSKfCXUCG1HKlj3nq8wJdvT
0dM6S94JTA0PazIauoI+xk7o0gEUCP49Z2ZEohGKTfDbyRIb+k0g3atLn+8UiQ5H
X8Oc6Ion4hjZGC+tGNZ1aRzCbB62Lc8Ems0+s56eoB/mJPzRyRvlRLOLegCNvsVD
RS8dlLYn+tH31K+EjIoFhYdE/ME5/PUX36SlkooW5POI/Aneblha8PqqAO/JNwPx
O9rMKVsW8NNmV7NCMh7V+CeDYW1O2A2pcN2KVIj6VcK1t7FcpZpctENxnZnBnb3m
ncn8DJC/8Tiq11s05YT+YcJro7oqIckfWkpa3FA9d+oXla6DcVrvHe/BsoNH0MKD
UpACtePpDjdoM0C7H4S3+h18SZDfn6kbdH+uOGaojG8NDmIeTbnMX4Mm1phfKtFr
FOfgDlU+6q/5mvU4Jd+M7LhgRUUGUW0+PPX1OGoKnLjfpYCdFyhOotfJPxRgstZH
EPqkuvsrQoVL9QM7WT6mN5ENmLacho3SAY1c//Jw5hi6O46p+VXgmoSggBMpjZaS
1GngYfMDPo3/IQY6S0fLYzZhyLbwJDtRAZEMsIOLl4zqGRltWt8=
=FMGp
—–END PGP SIGNATURE—–


