Cisco IOS XE Software Security Hardening Release: August 2026
TL;DR 📌
- As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To…
- Highest CVSS: 9.8 (Critical).
- Fix available — see the first fixed release below.
- CVEs: CVE-2026-20267, CVE-2026-20268, CVE-2026-20269.
What it is
This advisory covers seven CVEs found by Cisco’s own IOS XE engineering team during an internal security review, rather than through external reporting. Cisco has grouped the underlying bugs by CWE class and issued one CVE ID per class: CVE-2026-20267 (improper access control, CWE-284), CVE-2026-20268 (memory buffer bounds issues, CWE-119), CVE-2026-20269 (resource lifetime handling, CWE-664), CVE-2026-20270 (incorrect calculation, CWE-682), CVE-2026-20271 (control flow issues such as race conditions or uncontrolled recursion, CWE-691), CVE-2026-20272 (improper neutralisation of special elements, CWE-74, i.e. injection), and CVE-2026-20273 (improper input validation, CWE-20).
Each CVE score represents the highest-severity individual bug found within that CWE grouping, not a single specific flaw. CVE-2026-20272 (injection) and CVE-2026-20267 (access control) are rated CRITICAL/9.8 and 9.0 respectively; the remaining five are rated HIGH at 8.6. The CVSS vectors indicate network-based, no-privileges, no-user-interaction access across the group, with CVE-2026-20272 additionally scoped as unchanged (no impact beyond the vulnerable component) while the others show a changed scope.
The vulnerabilities affect Cisco IOS XE Software running in autonomous or controller mode, regardless of device configuration. Cisco’s review covered releases 17.9, 17.12, 17.15, 17.18, and 26.1; Catalyst 3650 and 3850 Series Switches were not evaluated as they don’t run these releases. Cisco states it is not aware of any public disclosure or malicious use of these issues, and they are not listed in CISA’s Known Exploited Vulnerabilities catalogue.
What to do
- Treat this as a bundled hardening release rather than a single-issue patch: all seven CVEs apply broadly to IOS XE in autonomous or controller mode, so plan for a full upgrade rather than a targeted fix.
- There are no workarounds — upgrading is the only remediation path Cisco offers.
- Move to the first fixed release for your current train: 17.9.10, 17.12.8, 17.15.6, 17.18.4 (or 17.18.4a), or 26.1.2, as applicable.
- If you run Catalyst 3650 or 3850 Series Switches, note these were not evaluated in this review; watch for a separate advisory if Cisco confirms any of these issues affect that platform.
- Prioritise devices reachable from untrusted networks given the network-based, unauthenticated access vectors across this group, particularly ahead of the CVE-2026-20272 injection issue and CVE-2026-20267 access control issue, which carry the highest scores.
Fixed releases
| Affected release | First fixed release |
|---|---|
| 17.9 | 17.9.10 |
| 17.12 | 17.12.8 |
| 17.15 | 17.15.6 |
| 17.18 | 17.18.4, 17.18.4a |
| 26.1 | 26.1.2 |
For leadership ðŸ§
Executive summary. Risk is Critical (CVSS 9.8) across any Cisco kit you run. Vendor fixes are available; prioritise upgrade within 48-72 hours.
Why it matters:
- Exposure depends on deployment topology and which access paths reach the affected component.
- Treat internet-facing and management-plane instances as higher risk than internal-only ones.
- Keep monitoring for abnormal authentication and configuration events until upgrades complete.
Now / Next / Later:
- Now: confirm whether you run the affected versions, and check exposure of any that are internet-facing.
- Next: upgrade to the first fixed release in the table above, through an approved change window.
- Later: add a control check so builds cannot drift back onto a vulnerable train.