← All Advisories

Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet

Last refreshed2026-09-27

Status: UPDATED  |  Advisory ID: CVE-2026-20271

Key Details

CVECVE-2026-20271
CVSS Score / Version8.6 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsCisco IOS XE
Classified asCWE-691 (Insufficient Control Flow Management)
Exploitation prediction (EPSS)0.47% probability of exploitation in the next 30 days (38% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CiscoIOS XE
SubsystemsIndustrial Network - Routers/Firewalls
SectorsCritical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems

What to Know

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691.

What to Do

Monitor Cisco's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20271
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20271
Vendor advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ