The critical advisory addresses multiple vulnerability classes affecting Cisco Catalyst IOS XE deployments
The critical advisory addresses multiple vulnerability classes affecting Cisco Catalyst IOS XE deployments
The following platforms are known to be affected:
These vulnerabilities affect Cisco IOS XE Software when it is running in autonomous or controller mode, regardless of device configuration.
Additional Cisco Advisories
Alongside the advisory included in this Cyber Alert, Cisco has released critical hardening advice for Cisco Calalyst SD WAN Software (covered in Cyber Alert CC-4825 ) and other important security advisories covered in a notification - Cisco Advance Notification for Publication of August 5, 2026, Security Advisories
Cisco has published a security hardening advisory for Cisco IOS XE Software following a comprehensive internal security review. The update addresses multiple vulnerability classes including improper access control, improper input validation, memory handling issues, calculation errors, control flow weaknesses, and command injection vulnerabilities. Cisco states that these vulnerabilities were discovered during internal testing and are not known to be actively exploited.
To streamline disclosure, Cisco grouped vulnerabilities according to their underlying Common Weakness Enumeration (CWE) category and assigned a single CVE identifier to each group. Several of the vulnerability classes have high severity ratings, with the most severe vulnerability carrying a CVSS score of 9.8.
Successful exploitation could allow attackers to bypass security controls, execute arbitrary commands , gain unauthorised access, disrupt services, compromise system integrity, or otherwise affect the confidentiality, integrity, and availability of affected devices depending on the vulnerable component involved.
Edge devices often targeted by attackers
Edge devices like Cisco IOS XE are often internet-facing by design and are highly attractive targets to attackers. An increasing number of edge device vulnerabilities disclosed each year are rapidly exploited by attackers. The NHS England National CSOC assesses it is highly likely vulnerabilities discovered in edge devices will continue to be exploited as zero-day vulnerabilities, or shortly after vendor disclosure.
Organisations are strongly encouraged to follow NCSC-UK's vulnerability management guidance , including patching edge devices as soon as possible if a critical vulnerability is identified.
Affected organisations are urged to review , assess exposure, and prioritise applying relevant updates.
Cisco has released software updates to address these vulnerabilities and states that no workarounds are available.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.
Last edited: 6 August 2026 4:04 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
