Vulnerabilities · 173 days ago

Cisco Patches a Dozen IOS and IOS XE Flaws

Cisco released patches for a dozen high- and medium-severity vulnerabilities in IOS and IOS XE. Four defects (CVE-2026-20110, -20112, -20113, -20114) affecting Catalyst 9300 switches were publicly disclosed; two can be chained to escalate privileges and cause a persistent denial-of-service that required physical intervention in validated scenarios.

CVE-2026-20113

NVD KEV

CVSS 5.3 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.3% (20th percentile).

CVE-2026-20114

NVD KEV

CVSS 5.4 MEDIUM: a vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an… EPSS 0.3% (20th percentile).

CVE-2026-20112

NVD KEV

CVSS 4.8 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.2% (9th percentile).

CVE-2026-20110

NVD KEV

CVSS 6.5 MEDIUM: a vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of…

Timeline

Sources

2 sources covering this story

Entities

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-03-26

Editions

Related stories