Cisco IOS XE Software Multiple Vulnerabilities (CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20272, & CVE-2026-20273)

Cisco releases security patches to address seven vulnerabilities impacting Cisco IOS XE Software. Only one of these vulnerabilities has given a critical severity rating with a CVSS score of 9.0.

These vulnerabilities were disclosed during internal testing conducted by the Cisco team. The vulnerabilities are not known to be exploited in the wild.

Cisco IOS is a legacy, monolithic operating system, while Cisco IOS XE is its modern, modular, Linux-based successor. IOS XE combines the traditional IOS command-line interface (CLI) with a modern architecture, providing enhanced stability, scalability, and programmability for newer enterprise devices.

Vulnerability Description

CVE-2026-20267

This is an improper access control flaw that may lead to authentication bypass and privilege escalation.

CVE-2026-20268

This is an improper restriction of operations within the bounds of a memory buffer flaw that can lead to buffer overflows and out-of-bounds writes.

CVE-2026-20269

This is an improper control of a resource through its lifetime flaw that can affect memory and file handlers, null pointer dereferences, and invalid frees.

CVE-2026-20270

This is an incorrect calculation flaw that can cause arithmetic or numeric conversion errors including integer overflow, underflow, truncation.

CVE-2026-20271

This is an insufficient control flow management flaw that can cause infinite loops, uncontrolled recursion, and race conditions.

CVE-2026-20272

This is an improper neutralization of special elements flaw that can affect command, OS, and argument injection.

CVE-2026-20273

This is an improper input validation flaw that covers input validation, path traversal, and external path control.

Affected and Patched Versions

Affected Version First Fixed Release
17.9 17.9.10
17.12 17.12.8
17.15 17.15.6
17.18 17.18.4, 17.18.4a
26.1 26.1.2

For more information, please refer to the Cisco Security Advisory (cisco-sa-hardening-iosxe-V8NMuMZJ).

Qualys Detection

Qualys customers can scan their devices with QID 317863 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ