Denial of Service Vulnerability in Cisco IOS and IOS XE Due to Improper Packet Handling
CVE-2026-20301

8.6HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
5 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20301?

A vulnerability exists within the Extensible Messaging Client Protocol (XMCP) utilized by Cisco IOS Software and Cisco IOS XE Software. This security flaw permits unauthenticated remote attackers to craft and send malformed XMCP packets to affected devices, leading them to unexpectedly reload and thereby inducing a denial of service (DoS) condition. The absence of the need for an XMCP client username simplifies the exploitation process, highlighting significant security concerns for networks utilizing affected Cisco products.

Affected Version(s)

Cisco IOS XE Software 17.2.1a

Cisco IOS XE Software 16.12.1y

Cisco IOS XE Software 16.12.3s

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.