Record summary

CVE-2026-20270 has a selected CVSS score of 8.6 (high).

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List17.2.1aaffected
16.12.1yaffected
16.12.3saffected
16.7.1baffected
16.6.2affected
16.6.5affected
16.12.1waffected
16.9.1daffected
17.3.1affected
16.9.4caffected
16.7.1affected
17.2.1affected
Showing 12 of 268 version ranges

References

2