CVE-2026-20271 – Cisco IOS XE Software
“Critical and high-severity weaknesses put core network devices at risk of compromise and service disruption.”
Cisco software hardening releases address eight vulnerabilities in IOS XE Software. CVE-2026-20272 has a CVSS score of 9.8, Critical severity. CVE-2026-20267 has a CVSS score of 9.0, Critical severity. CVE-2026-20263, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, and CVE-2026-20273 each have a CVSS score of 8.6, High severity.
The vulnerabilities span access control, memory handling, input validation, resource management, control flow, and special-element neutralization. The BEEP vulnerability can allow an unauthenticated remote attacker to force an affected device to reload, causing denial of service, while the memory-handling flaw presents code execution and privilege escalation risk.
Key Details
- Affected Product
- Cisco Ios Xe
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-691