Vulnerabilities & Exploits · DDoS
Cisco Patches a Dozen IOS and IOS XE Flaws Cisco released patches for a dozen high- and medium-severity vulnerabilities in IOS and IOS XE. Four defects (CVE-2026-20110 , -20112, -20113, -20114) affecting Catalyst 9300 switches were publicly disclosed; two can be chained to escalate privileges and cause a persistent denial-of-service that required physical intervention in validated scenarios.
2 sources · Mar 26
CVE-2026-20113 NVD KEV
CVSS 5.3 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.3% (20th percentile).
CVE-2026-20114 NVD KEV
CVSS 5.4 MEDIUM: a vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an… EPSS 0.3% (20th percentile).
CVE-2026-20112 NVD KEV
CVSS 4.8 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.2% (9th percentile).
CVE-2026-20110 NVD KEV
CVSS 6.5 MEDIUM: a vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of…
Timeline Sources Mar 26 SecurityWeek
Cisco Patches Multiple Vulnerabilities in IOS Software
The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation.
original Mar 25 Cisco PSIRT
Cisco Security Advisory: Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.
original Mar 25 Cisco PSIRT
Cisco Security Advisory: Cisco IOS XE Software Lobby Ambassador Privilege Escalation Vulnerability
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-26
Every edition of this story: Cisco Patches a Dozen IOS and IOS XE Flaws
More from today
Vulnerabilities & Exploits · DDoS
Cisco Patches a Dozen IOS and IOS XE Flaws Cisco released patches for a dozen high- and medium-severity vulnerabilities in IOS and IOS XE. Four defects (CVE-2026-20110 , -20112, -20113, -20114) affecting Catalyst 9300 switches were publicly disclosed; two can be chained to escalate privileges and cause a persistent denial-of-service that required physical intervention in validated scenarios.
2 sources · Mar 26
CVE-2026-20113 NVD KEV
CVSS 5.3 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.3% (20th percentile).
CVE-2026-20114 NVD KEV
CVSS 5.4 MEDIUM: a vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an… EPSS 0.3% (20th percentile).
CVE-2026-20112 NVD KEV
CVSS 4.8 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.2% (9th percentile).
CVE-2026-20110 NVD KEV
CVSS 6.5 MEDIUM: a vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of…
Timeline Sources Mar 26 SecurityWeek
Cisco Patches Multiple Vulnerabilities in IOS Software
The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation.
original Mar 25 Cisco PSIRT
Cisco Security Advisory: Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.
original Mar 25 Cisco PSIRT
Cisco Security Advisory: Cisco IOS XE Software Lobby Ambassador Privilege Escalation Vulnerability
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-03-26
Every edition of this story: Cisco Patches a Dozen IOS and IOS XE Flaws
More from today