Bootloader Vulnerability in Cisco IOS XE Software for Catalyst Switches
CVE-2026-20104

6.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
25 March 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-20104?

A vulnerability exists in the bootloader of Cisco IOS XE Software that affects several models of Cisco Catalyst Switches. This issue arises from insufficient validation during the boot process, allowing an authenticated local attacker with level-15 privileges or an unauthenticated individual with physical access to manipulate the binaries loaded at boot time. Such exploitation could enable the execution of arbitrary code, effectively bypassing integral security checks and compromising the trust chain of the device. This security flaw highlights the importance of robust verification mechanisms in maintaining device integrity and preventing unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco IOS XE Software 16.12.8

Cisco IOS XE Software 16.12.6

Cisco IOS XE Software 16.12.6a

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.