CVE-2026-20272

Published Aug 5, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-20272 identifies a group of vulnerabilities within Cisco IOS XE software, stemming from the improper neutralization of special elements. This collection of internally discovered weaknesses is categorized under CWE-74, which broadly covers injection issues such as command injection, operating system command injection, and argument injection. Rather than a single, conventional vulnerability with a specific exploitation path, CVE-2026-20272 acts as an umbrella identifier for multiple related bugs. Cisco's engineering team uncovered these issues during a comprehensive internal security review, leading to the release of software hardening updates to address them.

Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
Source
psirt@cisco.com
NVD status
Modified
Products
ios_xe

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@cisco.com
CWE-74

Social media

Hype score
Not currently trending
  1. CVE-2026-20272 — Critical Cisco IOS XE Software Vulnerability (CVE-2026-20272) https://t.co/0ZFy2w6EEw

    @security4ai

    3 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Cisco IOS XEのハードニング更新で7件を修正、CVE-2026-20272はCVSS 9.8 https://t.co/pswIeQADn9 #IT #Security #cybersecurity

    @Teeeda_worker

    16 Aug 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Cisco issued 12 advisories disclosing 23 vulnerabilities, with Critical-rated flaws in Catalyst SD-WAN and IOS XE. SD-WAN issues CVE-2026-20303, CVE-2026-20304 and CVE-2026-20310 each score 9.9 on CVSSv3.1. IOS XE flaws include CVE-2026-20272 (9.8) and CVE-2026-20267 (9.0).

    @WorldCyberNewsX

    8 Aug 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. > IOS XEでは7件の脆弱性が修正され、CVE-2026-20272(中略)とCVE-2026-20267(中略)は深刻度が「Critical」、残り5件は「High」となっている。 なんと。 シスコ、SD-WANやIOS XEなど複数製品の深刻な脆弱性を多数修正

    @PutStickerOn

    7 Aug 2026

    1586 Impressions

    3 Retweets

    8 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Cisco has patched two critical IOS XE vulnerabilities. CVE-2026-20272 is rated CVSS 9.8, while CVE-2026-20267 scores 9.0. Cisco is urging customers to patch immediately to reduce the risk of exploitation. #Cisco #IOSXE #CVE #CyberSecurity #NetworkSecurity #Infosec

    @ThreatWire_

    5 Aug 2026

    879 Impressions

    3 Retweets

    10 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  6. Cisco IOS XE vulnerability CVE-2026-20272 hits CVSS 9.8 and CVE-2026-20267 scores 9.0. Cisco urges customers to patch now. #Cisco #IOSXE #CVE202620272 #CVE202620267 #CyberSecurity #NetworkSecurity https://t.co/RzZ5mEYgCH

    @Daily_CyberSec

    5 Aug 2026

    399 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations