[CIVN-2026-0397] Multiple Vulnerabilities in Cisco IOS XE Software

By Published On: August 11, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Cisco IOS XE Software


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Cisco IOS XE Software (multiple releases as identified by Cisco Software Checker)

Cisco IOS Software (for the XMCP advisory)

Overview


Multiple vulnerabilities have been identified in Cisco IOS XE Software that could allow an attacker to execute arbitrary code, cause denial of service (DoS), bypass security restrictions, or compromise the confidentiality, integrity, and availability of the affected devices.


Target Audience:

Individuals and organizations using Cisco IOS XE Software and Cisco IOS Software.


Risk Assessment:

High risk of remote code execution, denial of service, security restriction bypass, and compromise of critical network infrastructure.


Impact Assessment:

Potential remote code execution, denial of service, security restriction bypass, and disruption of network operations.


Description


Cisco IOS XE Software is a network operating system used on Cisco enterprise routers, switches, wireless controllers, and other networking devices.


Multiple vulnerabilities have been reported in Cisco IOS XE Software due to Unchecked Input for Loop Condition, Error Handling, Missing Release of Resource after Effective Lifetime, Improper Access Control, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Control of a Resource Through its Lifetime, Incorrect Calculation, Insufficient Control Flow Management, Improper Neutralization of Special Elements in Output Used by a Downstream Component (‘Injection’), and Improper Input Validation.


Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, cause denial of service (DoS), bypass security restrictions, inject malicious input, access unauthorized resources, or compromise the confidentiality, integrity, and availability of the affected devices.


Solution


Apply appropriate updates as mentioned by the vendor

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/home.x


References


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t


CVE Name

CVE-2026-20301

CVE-2026-20263

CVE-2026-20124

CVE-2026-20267

CVE-2026-20268

CVE-2026-20269

CVE-2026-20270

CVE-2026-20271

CVE-2026-20272

CVE-2026-20273




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7DBgACgkQ3jCgcSdc

ys9Hgw//fjO6lydIb8idQEbbBboN6XDfVp92v93963TLiEhegpX7anp0TdfnXLF7

X7qNkO6FSIeTlov9eFnlqD3zfVqx7VtjzYb7hC/PexSKfCXUCG1HKlj3nq8wJdvT

0dM6S94JTA0PazIauoI+xk7o0gEUCP49Z2ZEohGKTfDbyRIb+k0g3atLn+8UiQ5H

X8Oc6Ion4hjZGC+tGNZ1aRzCbB62Lc8Ems0+s56eoB/mJPzRyRvlRLOLegCNvsVD

RS8dlLYn+tH31K+EjIoFhYdE/ME5/PUX36SlkooW5POI/Aneblha8PqqAO/JNwPx

O9rMKVsW8NNmV7NCMh7V+CeDYW1O2A2pcN2KVIj6VcK1t7FcpZpctENxnZnBnb3m

ncn8DJC/8Tiq11s05YT+YcJro7oqIckfWkpa3FA9d+oXla6DcVrvHe/BsoNH0MKD

UpACtePpDjdoM0C7H4S3+h18SZDfn6kbdH+uOGaojG8NDmIeTbnMX4Mm1phfKtFr

FOfgDlU+6q/5mvU4Jd+M7LhgRUUGUW0+PPX1OGoKnLjfpYCdFyhOotfJPxRgstZH

EPqkuvsrQoVL9QM7WT6mN5ENmLacho3SAY1c//Jw5hi6O46p+VXgmoSggBMpjZaS

1GngYfMDPo3/IQY6S0fLYzZhyLbwJDtRAZEMsIOLl4zqGRltWt8=

=FMGp

—–END PGP SIGNATURE—–

Share this article