CVE-2026-20272
CVSS 9.8 CRITICAL: as part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.
Vulnerabilities & Exploits
Cisco’s IOS XE patch set is the real story here. Seven separate high-severity flaws across access control, memory handling, resource control, flow management, injection, and input validation point to a codebase with multiple broken guardrails, not one isolated bug.
NCSC says Cisco found the issues during an internal security review and shipped updates for Cisco IOS XE Software. The CVEs run from CVE-2026-20267 through CVE-2026-20273, with CVSS scores from 8.6 to 9.8, and there is no exploitation signal attached to this advisory.
For operators, the immediate read is simple: verify IOS XE patch status. The useful warning is that one fixed flaw does not mean the platform is otherwise clean when the same review turned up this many distinct failure classes in core network software.
8 sources · Aug 7
CVSS 9.8 CRITICAL: as part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.
CVSS 9 CRITICAL: as part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.
NCSC-NL Advisories
Kwetsbaarheden verholpen in Cisco IOS XE Software
Cisco heeft meerdere kwetsbaarheden verholpen in Cisco IOS XE Software.
originalThe Hacker News
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
Cisco patches 12 Catalyst SD-WAN and IOS XE flaws, including three 9.9-rated bugs and a 9.8 command injection issue.
originalCSIRT Italia / ACN
Risolte vulnerabilità in prodotti Cisco
In particolare si evidenziano la CVE-2026-20316 che risulta attivamente sfruttata in rete e la CVE-2026-20200 per la quale è disponibile un Proof of Concept (PoC).
originalPart of the PlainSec briefing for 2026-08-08
Every edition of this story: Cisco IOS XE Fixes Expose Broader Codebase Weaknesses