Cisco Patches 7 IOS XE Vulnerabilities, Including Critical Command Injection Flaws
Cisco has released security-hardening updates for its IOS XE Software to address seven classes of vulnerabilities, including critical command injection flaws.
The advisory, released on August 5, affects Cisco IOS XE Software operating in either autonomous or controller mode, regardless of device configuration.
The most severe vulnerability, CVE-2026-20272, has a CVSS score of 9.8 and corresponds to CWE-74, which covers command injection, OS command injection, and argument injection.
Cisco urges customers to upgrade affected devices to IOS XE versions 17.9.10, 17.12.8, 17.15.6, 17.18.4, or 26.1.2, depending on their current release.