CVE-2026-20271: Cisco IOS XE Insufficient Control Flow Management
August 6, 2026
CVE-2026-20271 is a high-severity vulnerability in Cisco IOS XE Software with a CVSS score of 8.6. It is caused by insufficient control flow management, including infinite loops, uncontrolled recursion, and race conditions. Cisco has released fixes in versions 17.9.10, 17.12.8, 17.15.6, 17.18.4/17.18.4a, and 26.1.2.