Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.0

CVE-2026-20267: Cisco IOS XE Software Improper Access Control

CVE-2026-20267 CVE-2026-20267
Summary

Cisco IOS XE Software has multiple security weaknesses that can be exploited by unauthorized users. This can lead to unauthorized access or control of the system. Cisco has released updates to address these issues, and it's recommended to apply the latest patches to ensure system security.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
cisco cisco ios xe software 17.2.1a
Original title
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resul...
Original description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
mitre CVSS3.1 9.0
Vulnerability type
CWE-284 Improper Access Control
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026