nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-20270 CVE-2026-20270
HIGH
Cisco IOS XE Software Security Hardening Release
Record summary
CVE-2026-20270 has a selected CVSS score of 8.6 (high).
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Cisco IOS XE SoftwareBrowse Cisco / Cisco IOS XE SoftwareDefault status: unknown | CVE List | 17.2.1a | affected |
| 16.12.1y | affected | ||
| 16.12.3s | affected | ||
| 16.7.1b | affected | ||
| 16.6.2 | affected | ||
| 16.6.5 | affected | ||
| 16.12.1w | affected | ||
| 16.9.1d | affected | ||
| 17.3.1 | affected | ||
| 16.9.4c | affected | ||
| 16.7.1 | affected | ||
| 17.2.1 | affected | ||
| Showing 12 of 268 version ranges | |||
References
2cisco-sa-hardening-iosxe-V8NMuMZJ
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ