Junglewise Threat Intelligence

CVE-2026-20301: Cisco IOS and IOS XE denial of service in XMCP

CVE-2026-20301 · Severity: high · CVSS 8.6 · Published 2026-08-05

Executive brief

Cisco IOS and IOS XE devices with the XMCP (Extensible Messaging Client Protocol) Server feature enabled are vulnerable to remote denial of service attacks. An unauthenticated attacker can send a specially crafted network packet to cause the affected router or switch to crash and restart, disrupting all network traffic passing through that device. This vulnerability requires no authentication or user interaction.

Technical details

This vulnerability exists in the XMCP (Extensible Messaging Client Protocol, also called External Client protocol) implementation of Cisco IOS and IOS XE Software due to improper validation of malformed XMCP packets (CWE-606). An unauthenticated, remote attacker can exploit this by sending a crafted XMCP packet to a device with the XMCP Server feature enabled (configured via the "service-routing xmcp listen" command). A successful exploit causes the affected device to reload unexpectedly, resulting in a complete denial of service for all traffic transiting that device. No valid XMCP client credentials or prior access is required. Patches are available; Cisco also provides a temporary mitigation using access control lists to restrict XMCP connections to trusted clients only.

Affected products

  • Cisco IOS Software Multiple versions with XMCP Server feature enabled (see Cisco Software Checker for specific releases)
  • Cisco IOS XE Software Multiple versions with XMCP Server feature enabled (see Cisco Software Checker for specific releases)

Timeline

  • 2026-08-05: disclosed: Vulnerability disclosed by Cisco

References

Related threats