Bootloader Vulnerability in Cisco IOS XE Software for Catalyst Switches
CVE-2026-20104
What is CVE-2026-20104?
A vulnerability exists in the bootloader of Cisco IOS XE Software that affects several models of Cisco Catalyst Switches. This issue arises from insufficient validation during the boot process, allowing an authenticated local attacker with level-15 privileges or an unauthenticated individual with physical access to manipulate the binaries loaded at boot time. Such exploitation could enable the execution of arbitrary code, effectively bypassing integral security checks and compromising the trust chain of the device. This security flaw highlights the importance of robust verification mechanisms in maintaining device integrity and preventing unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XE Software 16.12.8
Cisco IOS XE Software 16.12.6
Cisco IOS XE Software 16.12.6a
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved