Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026080605080303 | Publication Time | 2026-08-06 17:21:04 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-08-06 17:21:04 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Cisco IOS XE Software Contains Two Critical Cybersecurity Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000004 The Cisco IOS XE software development team discovered multiple security vulnerabilities during an internal security review and has completed remediation. Currently, there is no evidence indicating that these vulnerabilities are being actively exploited. To assist customers in deploying security updates in a timely manner and simplify the vulnerability disclosure process, Cisco has publicly released the relevant vulnerability information and remediation recommendations. CVE-2026-20267 (CVSS: 9.0) is an Improper Access Control vulnerability; CVE-2026-20272 (CVSS: 9.8) is an Improper Neutralization of Special Elements vulnerability. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Cisco IOS XE version 17.9, Cisco IOS XE version 17.12, Cisco IOS XE version 17.15, Cisco IOS XE version 17.18, Cisco IOS XE version 26.1 |
|||
|
[Recommended Actions] Please update to the following versions: Cisco IOS XE version 17.12.18 or later, Cisco IOS XE version 17.15.6 or later, Cisco IOS XE version 17.18.4 or later, Cisco IOS XE version 17.18.4a or later, Cisco IOS XE version 26.1.2 or later |
|||
|
[Reference] 1. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ |
|||