Improper Input Validation in Cisco IOS XE Software
CVE-2026-20273

8.6HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
5 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20273?

The Cisco IOS XE Software has been found to contain vulnerabilities related to improper input validation. These weaknesses can potentially lead to security issues if exploited. Cisco has responded by implementing a software hardening release through a comprehensive internal security review, aimed at addressing these vulnerabilities effectively. It is essential for users of affected versions to apply the updates to ensure their systems remain secure.

Affected Version(s)

Cisco IOS XE Software 17.2.1a

Cisco IOS XE Software 16.12.1y

Cisco IOS XE Software 16.12.3s

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.