Cisco Patches Critical IOS XE Vulnerabilities with August 5 Security Updates
Cisco has released security updates for its IOS XE Software to address seven classes of vulnerabilities. The patches, released on August 5, cover a range of issues including critical command injection flaws and improper access control weaknesses.
The most severe vulnerability, CVE-2026-20272, is associated with CWE-74 and has a CVSS score of 9.8. This indicates that it can be exploited by a network-accessible attack requiring no privileges or user interaction, potentially affecting confidentiality, integrity, and availability.
Cisco evaluated releases 17.9, 17.12, 17.15, 17.18, and 26.1, but excluded the Catalyst 3650 and 3850 switches from this assessment because they do not run these release trains.