CVE-2026-20301
CVE-2026-20301 is a high-severity vulnerability in Cisco Ios with a CVSS 3.x base score of 8.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-606.
Key facts
- Severity: High (CVSS 3.x base score 8.6)
- EPSS exploit prediction: 1% (46th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-606
- Affected product: Cisco Ios
- Published:
- Last modified:
Description
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.
Frequently asked questions
- What is CVE-2026-20301?
- A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.
- How severe is CVE-2026-20301?
- CVE-2026-20301 has a CVSS 3.x base score of 8.6, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-20301 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (46th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-20301?
- CVE-2026-20301 primarily affects Cisco Ios. In total, 427 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-20301?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-20301 published?
- CVE-2026-20301 was published on 2026-08-05 and last updated on 2026-09-17.
References
Affected products (427)
- cpe:2.3:o:cisco:ios:15.2\(1\)sy6:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(1\)sy7:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(1\)sy8:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(2\)e8:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(2\)e9:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(2\)e9a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(2\)e10:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(2\)e10a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(2\)e10b:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(2\)e10c:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e6:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e7:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e8:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e9:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e10:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e10a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e10b:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e10c:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e10d:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)e10e:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)ea7:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)ea8:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)ea9:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(4\)ea9a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(6\)e1:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(6\)e1a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(6\)e1s:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(6\)e2:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(6\)e2a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(6\)e2b:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(6\)e3:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e0a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e0b:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e0s:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e1:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e1a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e2:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e2b:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.2\(7\)e3:*:*:*:*:*:*:*
More vulnerabilities in Cisco Ios
- CVE-2011-3271 — Critical (CVSS 10.0): Unspecified vulnerability in the Smart Install functionality in Cisco IOS 12.2 and 15.1 allows remote attackers to…
- CVE-2011-0935 — Critical (CVSS 10.0): The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which…
- CVE-2010-1574 — Critical (CVSS 10.0): IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of…
- CVE-2010-0581 — Critical (CVSS 10.0): Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute…
- CVE-2010-0580 — Critical (CVSS 10.0): Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute…
- CVE-2006-4950 — Critical (CVSS 10.0): Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices,…
All CVEs affecting Cisco Ios →
Other CWE-606 vulnerabilities
- CVE-2026-13761 — High (CVSS 8.8): Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop…
- CVE-2026-85730 — High (CVSS 8.2): smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop…
- CVE-2026-27689 — High (CVSS 7.7): Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular…
- CVE-2026-62901 — High (CVSS 7.5): Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-1519 — High (CVSS 7.5): If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume…
- CVE-2025-43801 — High (CVSS 7.5): Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older…