Denial of Service Vulnerability in Cisco Network Convergence System
CVE-2026-20118
6.8MEDIUM
What is CVE-2026-20118?
A vulnerability in the Egress Packet Network Interface (EPNI) Aligner interrupt handling in Cisco's IOS XR Software could allow unauthenticated remote attackers to disrupt the network by stopping crucial network processing components. This flaw can be exploited when an affected device experiences heavy transit traffic, leading to packet corruption. An attacker can leverage this vulnerability to send crafted packets continuously, potentially causing significant packet loss and resulting in a denial of service condition. For organizations relying on Cisco NCS devices in critical network segments, this issue poses a substantial risk of network disruption.
Affected Version(s)
Cisco IOS XR Software 7.9.1
Cisco IOS XR Software 7.10.1
Cisco IOS XR Software 7.9.2