Executive brief
Cisco IOS XE is the operating system running on Cisco network switches and routers used to manage enterprise networks. This vulnerability involves improper handling of system resources (memory and file handlers) during their lifecycle, which could allow an attacker to cause service disruptions or potentially execute code remotely. Cisco has released patched software versions to address this issue, with no known active exploitation at this time.
Technical details
CVE-2026-20269 is one of seven vulnerabilities in a Cisco software hardening release addressing improper resource lifetime control issues grouped under CWE-664. This class of weakness includes memory and file handler management, null pointer dereferences, and invalid free operations. The vulnerability affects Cisco IOS XE Software running in autonomous or controller mode across multiple product lines (excluding Catalyst 3650 and 3850 Series). Attack vector is network-based with no authentication or user interaction required (CVSS 8.6). Cisco has released fixed versions for affected release trains (17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, 26.1.2) and indicates no workarounds are available.
Affected products
- Cisco IOS XE 17.9 before 17.9.10, 17.12 before 17.12.8, 17.15 before 17.15.6, 17.18 before 17.18.4, 26.1 before 26.1.2
Timeline
- 2026-08-05: disclosed: CVE-2026-20269 published by Cisco
- 2026-08-05: patched: Fixed releases available: 17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, 26.1.2