< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Cisco issues emergency patch for critical IOS XE security flaws

Cisco released an emergency security update for its IOS XE operating system on 6 August 2026. The patch addresses seven newly discovered vulnerabilities, the most severe being CVE‑2026‑20272, which received a CVSS rating of 9.8 and could allow remote code execution. Additional flaws include CVE‑2026‑20267 (CVSS 9.0) and five others rated 8.6, covering issues such as improper access control, buffer overflows, and input validation errors.

Cisco advises that no work‑arounds exist and that affected devices must be updated immediately. The advisory covers IOS XE releases 17.9, 17.12, 17.15, 17.18 and 26.1, regardless of configuration mode. The company reported no known public exploitation of the flaws. The update is critical for enterprises that rely on Cisco network equipment worldwide.

Entities

CVE-2026-20272 · Cisco · IOS XE