Cisco non sta correggendo un buco singolo, ma una base di codice che ha retto male su più fronti indipendenti. Per chi gestisce IOS XE, il punto non è l’emergenza: è che controllo degli accessi, memoria, risorse, flow e input validation hanno mostrato debolezze nello stesso prodotto.
Il NCSC olandese segnala che Cisco ha scoperto internamente sette vulnerabilità in Cisco IOS XE Software, tutte già corrette con aggiornamenti software. Le CVE vanno da CVE-2026-20267 a CVE-2026-20273, con severità alta fino a 9.8; non c’è segnale di sfruttamento attivo né un contesto di campagna più ampio.
Per le reti che usano router e switching Cisco come infrastruttura core, il messaggio utile è la verifica dello stato di patch: una correzione non implica che il resto della base di codice sia pulito.
CVSS 9.8 CRITICAL: as part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.
CVSS 9 CRITICAL: as part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.
In particolare si evidenziano la CVE-2026-20316 che risulta attivamente sfruttata in rete e la CVE-2026-20200 per la quale è disponibile un Proof of Concept (PoC).
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.