CVE-2026-20267
Cisco IOS XE Software Security Hardening Release
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
In plain language
AI Act nowThis is a serious security issue in Cisco IOS XE Software; businesses using it should act now because public attack code is available.
Critical improper-access-control hardening release for Cisco IOS XE Software, covering multiple internally discovered CWE-284 issues; public exploit code is available.
What to do now
- Check whether your routers, switches, or wireless controllers run Cisco IOS XE Software and compare their release train with Cisco’s advisory.
- Install the Cisco remediation release specified for your device and release train; the supplied findings do not identify a single exact fixed version.
- If upgrading must wait, restrict management access to trusted internal networks and contact Cisco or your support partner for the applicable remediation release.
- Review device logs and configuration changes for unexpected administrator activity after remediation.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoorsen·The Hacker News· Exploited Mythos 5 UNC6671
- Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugsen·The Hacker News· Advisory Cisco Catalyst SD-WAN Software rce
- Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilitiesen-us·SecurityWeek· Patch SD-WAN rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20267 and every CVE in our database. Create a free account — no credit card required.
Create Free Account