CVE-2026-20267 – Cisco IOS XE Software

CVSS 9 CRITICAL Critical - Same Day Deployment

“The strongest defenses are built by fixing hidden weaknesses before they become visible attacks.”

Cisco has released software hardening updates for Cisco IOS XE Software following a comprehensive internal security review. The updates address multiple internally discovered vulnerabilities involving improper neutralization of special elements and improper access control, strengthening the security of affected systems.

CVE-2026-20272 has a CVSS score of 9.8, Critical severity. CVE-2026-20267 has a CVSS score of 9.0, Critical severity. No verified public proof-of-concept code or real-world exploitation has been confirmed for these vulnerabilities.

Key Details

Affected Product
Cisco Ios Xe
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-284
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.