Junglewise Threat Intelligence

CVE-2026-20270: Cisco IOS XE Software incorrect calculation vulnerability

CVE-2026-20270 · Severity: high · CVSS 8.6 · Published 2026-08-05

Executive brief

Cisco IOS XE Software contains multiple calculation and validation errors that were discovered during an internal security review. These vulnerabilities affect network switches and routing equipment running IOS XE in autonomous or controller mode. An attacker with network access could exploit these issues to cause crashes, data corruption, or other impacts depending on the specific flaw.

Technical details

CVE-2026-20270 is a numeric calculation error (CWE-682) grouped with other vulnerabilities discovered during Cisco's internal security review of IOS XE Software. The vulnerability affects Cisco IOS XE running in autonomous or controller mode on network devices. The exact attack vector requires network access with no authentication or user interaction required. The flaw falls within a broader set of seven related vulnerabilities (CVE-2026-20267 through CVE-2026-20273) covering improper access control, buffer overflows, resource lifetime issues, calculation errors, control flow management, command injection, and input validation flaws. Fixes are available in patched releases: 17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, and 26.1.2. No workarounds are available.

Affected products

  • Cisco IOS XE 17.9 (before 17.9.10), 17.12 (before 17.12.8), 17.15 (before 17.15.6), 17.18 (before 17.18.4), 26.1 (before 26.1.2)

Timeline

  • 2026-08-05: disclosed
  • 2026-08-05: patched: Fixed releases available: 17.9.10, 17.12.8, 17.15.6, 17.18.4, 26.1.2

References

Related threats