Executive brief
Cisco IOS XE is networking device operating system software used to power switches, routers, and other infrastructure equipment. A vulnerability in control flow management could allow an attacker to cause system instability, service disruption, or other impacts depending on the specific code path exploited. This was discovered during an internal security review and is not currently known to be exploited.
Technical details
CVE-2026-20271 tracks insufficient control flow management issues (CWE-691) found in Cisco IOS XE Software during internal security testing. The vulnerability affects IOS XE in both autonomous and controller modes, with a maximum CVSS score of 8.6 indicating high severity. Attack vector is network-based with no authentication or user interaction required. Cisco has released fixed software versions (17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, and 26.1.2) that address this and related issues. No workarounds are available.
Affected products
- Cisco IOS XE 17.9, 17.12, 17.15, 17.18, 26.1
Timeline
- 2026-08-05: disclosed