CVE-2026-20272
Cisco IOS XE Software Security Hardening Release
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugsen·The Hacker News· Advisory Cisco Catalyst SD-WAN Software rce
- Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)en-us·Help Net Security· PoC Integrated Management Controller (IMC) rce
- Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilitiesen-us·SecurityWeek· Patch SD-WAN rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20272 and every CVE in our database. Create a free account — no credit card required.
Create Free Account