Cisco Patches Seven Critical IOS XE Vulnerabilities Discovered Internally
Cisco has released a security hardening update for IOS XE Software to fix seven critical vulnerabilities, including one that could allow attackers to execute code remotely.
The vulnerabilities were discovered through internal testing using existing QA processes and frontier AI models. The most severe flaw, rated CVSS 9.8, enables injection attacks that can lead to full remote code execution with no authentication required.
Cisco has grouped the bugs by underlying Common Weakness Enumeration (CWE) class rather than issuing a separate CVE per bug. The advisory carries a Critical severity rating overall, with no available workarounds.