Skip to content
CiscoCVE-2026-20301

Cisco IOS XE Software: denial of service

High8.6CVE-2026-20301 · Published Aug 5, 2026 · updated Sep 17, 2026

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco IOS XE Software
Product
<= 17.2.1aNo fix yet
<= 16.12.1yNo fix yet
<= 16.12.3sNo fix yet
<= 16.7.1bNo fix yet
IOS
Product
<= 15.2(7)E7No fix yet
<= 15.2(8)E3No fix yet
<= 15.7(3)M10No fix yet
<= 15.8(3)M9No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Catalyst SD-WAN: cleartext secrets
High8.8Aug 5
Cisco Catalyst SD-WAN: improper quantity validation
High7.7Aug 5
Cisco IOS XE Software: denial of service
Medium4.3Aug 5
Cisco Catalyst SD-WAN: link following
Critical9.1Aug 5
Cisco IOS XE Software: denial of service
Medium6.3Aug 5
Cisco Catalyst SD-WAN: improper input validation
Critical9.9Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.