← All Advisories

Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service

Last refreshed2026-09-27

Status: UPDATED  |  Advisory ID: CVE-2026-20269

Key Details

CVECVE-2026-20269
CVSS Score / Version8.6 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsCisco IOS XE
Classified asCWE-664 (Improper Control of a Resource Through its Lifetime)
Exploitation prediction (EPSS)0.47% probability of exploitation in the next 30 days (38% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CiscoIOS XE
SubsystemsIndustrial Network - Routers/Firewalls
SectorsCritical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems

What to Know

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

What to Do

Monitor Cisco's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20269
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20269
Vendor advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ