Junglewise Threat Intelligence

CVE-2026-20273: Cisco IOS XE Software improper input validation

CVE-2026-20273 · Severity: high · CVSS 8.6 · Published 2026-08-05

Executive brief

Cisco IOS XE Software, used in network switches and routers, contains multiple vulnerabilities related to improper input validation and other security weaknesses discovered during an internal security review. An attacker with network access could exploit these flaws to gain unauthorized access, execute commands, or disrupt network device operations without authentication.

Technical details

CVE-2026-20273 is part of a grouped disclosure addressing multiple internally discovered vulnerabilities in Cisco IOS XE Software, categorized under CWE-20 (improper input validation) among others. The vulnerabilities affect IOS XE versions 17.9, 17.12, 17.15, 17.18, and 26.1 running in autonomous or controller mode. The attack vector is network-based with no authentication required (CVSS vector AV:N/AC:L/PR:N/UI:N). Cisco has released patched versions for each affected branch (17.9.10, 17.12.8, 17.15.6, 17.18.4/4a, 26.1.2). No workarounds are available; patching is required to remediate.

Affected products

  • Cisco IOS XE 17.9, 17.12, 17.15, 17.18, 26.1

Timeline

  • 2026-08-05: disclosed

References

Related threats