Cisco IOS XE Software Security Hardening Release: August 2026
TL;DR π
- As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. Toβ¦
- Highest CVSS: 9.8 (Critical).
- Fix available β see the first fixed release below.
- CVEs: CVE-2026-20267, CVE-2026-20268, CVE-2026-20269.
What it is
This advisory covers seven CVEs found by Cisco’s own IOS XE engineering team during an internal security review, rather than through external reporting. Cisco has grouped the underlying bugs by CWE class and issued one CVE ID per class: CVE-2026-20267 (improper access control, CWE-284), CVE-2026-20268 (memory buffer bounds issues, CWE-119), CVE-2026-20269 (resource lifetime handling, CWE-664), CVE-2026-20270 (incorrect calculation, CWE-682), CVE-2026-20271 (control flow issues such as race conditions or uncontrolled recursion, CWE-691), CVE-2026-20272 (improper neutralisation of special elements, CWE-74, i.e. injection), and CVE-2026-20273 (improper input validation, CWE-20).
Each CVE score represents the highest-severity individual bug found within that CWE grouping, not a single specific flaw. CVE-2026-20272 (injection) and CVE-2026-20267 (access control) are rated CRITICAL/9.8 and 9.0 respectively; the remaining five are rated HIGH at 8.6. The CVSS vectors indicate network-based, no-privileges, no-user-interaction access across the group, with CVE-2026-20272 additionally scoped as unchanged (no impact beyond the vulnerable component) while the others show a changed scope.
The vulnerabilities affect Cisco IOS XE Software running in autonomous or controller mode, regardless of device configuration. Cisco’s review covered releases 17.9, 17.12, 17.15, 17.18, and 26.1; Catalyst 3650 and 3850 Series Switches were not evaluated as they don’t run these releases. Cisco states it is not aware of any public disclosure or malicious use of these issues, and they are not listed in CISA’s Known Exploited Vulnerabilities catalogue.
What to do
- Treat this as a bundled hardening release rather than a single-issue patch: all seven CVEs apply broadly to IOS XE in autonomous or controller mode, so plan for a full upgrade rather than a targeted fix.
- There are no workarounds β upgrading is the only remediation path Cisco offers.
- Move to the first fixed release for your current train: 17.9.10, 17.12.8, 17.15.6, 17.18.4 (or 17.18.4a), or 26.1.2, as applicable.
- If you run Catalyst 3650 or 3850 Series Switches, note these were not evaluated in this review; watch for a separate advisory if Cisco confirms any of these issues affect that platform.
- Prioritise devices reachable from untrusted networks given the network-based, unauthenticated access vectors across this group, particularly ahead of the CVE-2026-20272 injection issue and CVE-2026-20267 access control issue, which carry the highest scores.
Fixed releases
| Affected release | First fixed release |
|---|---|
| 17.9 | 17.9.10 |
| 17.12 | 17.12.8 |
| 17.15 | 17.15.6 |
| 17.18 | 17.18.4, 17.18.4a |
| 26.1 | 26.1.2 |
For leadership π§
Executive summary. Cisco has grouped seven internally discovered IOS XE vulnerabilities into this hardening release, the worst of which allows unauthenticated network attackers to inject malicious input or bypass access controls on devices running in autonomous or controller mode. There is no workaround, so upgrading to the fixed release for your train is the only path to remediation and should be scheduled as a priority change.
Why it matters:
- CVE-2026-20272 (injection, CWE-74) and CVE-2026-20267 (access control, CWE-284) score 9.8 and 9.0, and like the rest of the group require no authentication or user interaction and are reachable over the network
- All seven CVEs apply broadly across IOS XE in autonomous or controller mode regardless of device configuration, so this is not a narrow edge-case fix but a fleet-wide patching exercise
- Cisco offers no workaround for any of these issues, meaning affected devices remain exposed until they are upgraded to the relevant fixed release
- Catalyst 3650 and 3850 Series Switches were excluded from Cisco’s review, so their exposure status is currently unknown pending any separate advisory
Now / Next / Later:
- Now: Identify every IOS XE device running in autonomous or controller mode on releases 17.9, 17.12, 17.15, 17.18 or 26.1, and check which are reachable from untrusted networks.
- Next: Upgrade each device to the first fixed release for its train (17.9.10, 17.12.8, 17.15.6, 17.18.4/17.18.4a, or 26.1.2), prioritising those exposed to untrusted networks given the unauthenticated network-based access vectors.
- Later: Build IOS XE hardening releases into a routine upgrade cadence, and track any follow-up advisory covering Catalyst 3650/3850 Series Switches, which were not evaluated in this review.