Junglewise Threat Intelligence

CVE-2026-20263: Cisco IOS XE BEEP denial of service

CVE-2026-20263 · Severity: high · CVSS 8.6 · Published 2026-08-05

Executive brief

Cisco IOS XE is the operating system that runs Cisco network devices such as routers and switches. The BEEP (Blocks Extensible Exchange Protocol) feature, when enabled, allows remote management of these devices. An unauthenticated attacker can exploit a flaw in BEEP's request parsing to crash the device unexpectedly, causing a service outage for network operations.

Technical details

This vulnerability exists in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software and stems from improper handling of SOAP request parsing (CWE-388). An unauthenticated, network-accessible attacker can send a specially crafted BEEP SOAP request to an affected device. The vulnerability requires BEEP to be configured (either NETCONF over BEEP or a BEEP listener via the bingd process), but does not require authentication or user interaction. Successful exploitation causes the device to reload unexpectedly, resulting in a denial of service condition. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco IOS XE Software Multiple releases with BEEP feature enabled (see Cisco Software Checker)

Timeline

  • 2026-08-05: disclosed

References

Related threats