Cisco releases security patches to address seven vulnerabilities impacting Cisco IOS XE Software. Only one of these vulnerabilities has given a critical severity rating with a CVSS score of 9.0.
These vulnerabilities were disclosed during internal testing conducted by the Cisco team. The vulnerabilities are not known to be exploited in the wild.
Cisco IOS is a legacy, monolithic operating system, while Cisco IOS XE is its modern, modular, Linux-based successor. IOS XE combines the traditional IOS command-line interface (CLI) with a modern architecture, providing enhanced stability, scalability, and programmability for newer enterprise devices.
Vulnerability Description
CVE-2026-20267
This is an improper access control flaw that may lead to authentication bypass and privilege escalation.
CVE-2026-20268
This is an improper restriction of operations within the bounds of a memory buffer flaw that can lead to buffer overflows and out-of-bounds writes.
CVE-2026-20269
This is an improper control of a resource through its lifetime flaw that can affect memory and file handlers, null pointer dereferences, and invalid frees.
CVE-2026-20270
This is an incorrect calculation flaw that can cause arithmetic or numeric conversion errors including integer overflow, underflow, truncation.
CVE-2026-20271
This is an insufficient control flow management flaw that can cause infinite loops, uncontrolled recursion, and race conditions.
CVE-2026-20272
This is an improper neutralization of special elements flaw that can affect command, OS, and argument injection.
CVE-2026-20273
This is an improper input validation flaw that covers input validation, path traversal, and external path control.
Affected and Patched Versions
| Affected Version | First Fixed Release |
| 17.9 | 17.9.10 |
| 17.12 | 17.12.8 |
| 17.15 | 17.15.6 |
| 17.18 | 17.18.4, 17.18.4a |
| 26.1 | 26.1.2 |
For more information, please refer to the Cisco Security Advisory (cisco-sa-hardening-iosxe-V8NMuMZJ).
Qualys Detection
Qualys customers can scan their devices with QID 317863 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.