Junglewise Threat Intelligence

CVE-2026-20272: Cisco IOS XE Software improper neutralization of special elements

CVE-2026-20272 · Severity: critical · CVSS 9.8 · Published 2026-08-05

Executive brief

Cisco IOS XE Software, which runs on network switches and routers, contains a critical vulnerability in how it processes special elements and commands. An unauthenticated attacker on the network can exploit this flaw to gain complete control over affected devices, compromise data, disrupt service, or launch further attacks into the network.

Technical details

CVE-2026-20272 encompasses improper neutralization of special elements (CWE-74), which includes command injection, OS injection, and argument injection vulnerabilities in Cisco IOS XE Software. The vulnerability affects devices running in autonomous or controller mode across multiple release trains (17.9, 17.12, 17.15, 17.18, and 26.1). An unauthenticated attacker on the network can send specially crafted input to trigger injection attacks that allow arbitrary command execution or privilege escalation. This is a network-reachable vulnerability requiring no authentication or user interaction. Cisco has released patched versions (17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, 26.1.2) and confirmed no known active exploitation.

Affected products

  • Cisco IOS XE 17.9 prior to 17.9.10, 17.12 prior to 17.12.8, 17.15 prior to 17.15.6, 17.18 prior to 17.18.4, 26.1 prior to 26.1.2

Timeline

  • 2026-08-05: disclosed
  • 2026-08-05: patched: Fixed releases available: 17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, 26.1.2

References

Related threats