Executive brief
Cisco IOS XE Software, used in enterprise network switches and routers, contains multiple memory buffer handling vulnerabilities discovered during internal security review. An attacker with network access could exploit these flaws to crash devices or potentially execute unauthorized code, disrupting network operations and compromising data integrity.
Technical details
CVE-2026-20268 covers improper restriction of operations within memory buffer bounds (CWE-119), including buffer overflows and out-of-bounds writes. The vulnerability affects Cisco IOS XE Software running in autonomous or controller mode on various network devices. The issue is remotely exploitable over the network without authentication or user interaction required. A successful exploit could allow an attacker to achieve high impact on confidentiality, integrity, and availability. Cisco has released fixed software versions for affected releases (17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, 26.1.2). No workarounds are available.
Affected products
- Cisco IOS XE 17.9, 17.12, 17.15, 17.18, 26.1
Timeline
- 2026-08-05: disclosed: Advisory published by Cisco PSIRT