Cisco Product Security Update Advisory

Cisco Product Security Update Advisory

Overview


Security updates addressing various vulnerabilities in Cisco products have been released. Users of affected products should update to the latest version.

Affected Products and Vulnerabilities


  • CVE-2026-20124. A denial-of-service vulnerability in Cisco IOS XE Software. Use the Cisco Software Checker to verify if your system is affected and to find the appropriate patch version.
  • CVE-2026-20200. This is an arbitrary command execution and privilege escalation vulnerability in Cisco UCS Server Software. Affected versions are those prior to 4.3, Prior to 4.3 (6.260033), And prior to 6.0 (2.260044).
  • CVE-2026-20263. This is a denial-of-service vulnerability in the BEEP feature of Cisco IOS XE Software. Use Cisco Software Checker to verify if your system is affected and to find the fixed version.
  • CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20272, CVE-2026-20273. These vulnerabilities in Cisco IOS XE Software include insufficient access control, insufficient memory buffer boundary enforcement, insufficient resource lifecycle management, incorrect calculations, insufficient control flow management, insufficient handling of special characters, and insufficient input validation. Affected versions are 17.9, 17.12, 17.15, 17.18, And 26.1.
  • CVE-2026-20301. This is a denial-of-service vulnerability in Cisco IOS and IOS XE Software. Use the Cisco Software Checker to verify whether your system is affected and to find the fixed versions.
  • CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313. These are vulnerabilities in Cisco Catalyst SD-WAN Software involving insufficient input validation, insufficient access control, insufficient pre-parsing of file access paths, storage of sensitive information in plain text, and insufficient validation of input quantities. Affected versions include those prior to 20.9, 20.9, 20.10, 20.11, 20.12, 20.13, 20.14, 20.15, 20.16, 20.18, And 26.1.

Fixed Versions


  • CVE-2026-20124. Update to a fixed version identified by Cisco Software Checker.
  • CVE-2026-20200. For versions earlier than 4.3, Update to a higher release where the vulnerability has been resolved. Versions 4.3 (6.260033) And later, and 6.0 (2.260044) And later are fixed versions.
  • CVE-2026-20263. Update to the fixed version identified by Cisco Software Checker.
  • CVE-2026-20267–CVE-2026-20273. The fixed versions are 17.9.10, 17.12.8, 17.15.6, 17.18.4, 17.18.4A, and 26.1.2.
  • CVE-2026-20301. Update to a fixed version identified by Cisco Software Checker.
  • CVE-2026-20303–CVE-2026-20313. For versions prior to 20.9, Update to a higher release where the vulnerability has been resolved. The fixed versions are 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, And 26.1.2.

Note


This advisory provides information on the latest security updates to address various vulnerabilities in Cisco IOS XE Software, Cisco UCS Server Software, Cisco IOS Software, and Cisco Catalyst SD-WAN Software. Affected environments must be promptly updated to the corrected versions as instructed on the reference site.