← All Advisories

Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component

Last refreshed2026-09-27

Status: UPDATED  |  Advisory ID: CVE-2026-20272

Key Details

CVECVE-2026-20272
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsCisco IOS XE
Classified asCWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'))
Exploitation prediction (EPSS)0.57% probability of exploitation in the next 30 days (45% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CiscoIOS XE
SubsystemsIndustrial Network - Routers/Firewalls
SectorsCritical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems

What to Know

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.

What to Do

Monitor Cisco's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20272
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20272
Vendor advisoryhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ