CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-20272: Cisco IOS XE Command Injection

August 6, 2026

CVE-2026-20272 is a critical vulnerability in Cisco IOS XE Software with a CVSS score of 9.8. It involves improper neutralization of special elements, including command, OS, and argument injection. Cisco has released fixes in versions 17.9.10, 17.12.8, 17.15.6, 17.18.4/17.18.4a, and 26.1.2.