CVE-2026-20271 Details
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691.
A vulnerability has been identified in Cisco IOS XE Software related to insufficient control flow management, which can lead to issues such as infinite loops, uncontrolled recursion, or race conditions. This vulnerability affects several different versions of Cisco IOS XE Software when it is running in autonomous or controller mode, regardless of device configuration. The vulnerability was discovered during an internal security review and is not known to be actively exploited.
To address this vulnerability, Cisco recommends upgrading to a fixed software release. The first fixed release for this vulnerability is Cisco IOS XE 17.9.10. For other affected versions, please refer to the Cisco Security Advisory for the specific fixed release information.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-691 | Insufficient Control Flow Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios xe | 16.6.2 16.6.3 16.6.4 16.6.4a 16.6.4s 16.6.5 16.6.5a 16.6.5b 16.6.6 16.6.7 16.6.7a 16.6.8 16.6.9 16.6.10 16.7.1 16.7.1a 16.7.1b 16.7.2 16.7.3 16.7.4 16.8.1 16.8.1a 16.8.1b 16.8.1c 16.8.1d 16.8.1e 16.8.1s 16.8.2 16.8.3 16.9.1 16.9.1a 16.9.1b 16.9.1c 16.9.1d 16.9.1s 16.9.2 16.9.2a 16.9.2s 16.9.3 16.9.3a 16.9.3h 16.9.3s 16.9.4 16.9.4c 16.9.5 16.9.5f 16.9.6 16.9.7 16.9.8 16.9.8a 16.9.8b 16.10.1 16.10.1a 16.10.1b 16.10.1c 16.10.1d 16.10.1e 16.10.1f 16.10.1g 16.10.1s 16.10.2 16.10.3 16.11.1 16.11.1a 16.11.1b 16.11.1c 16.11.1s 16.11.2 16.12.1 16.12.1a 16.12.1c 16.12.1s 16.12.1t 16.12.1w 16.12.1x 16.12.1y 16.12.1z 16.12.1z1 16.12.1z2 16.12.2 16.12.2a 16.12.2s 16.12.2t 16.12.3 16.12.3a 16.12.3s 16.12.4 16.12.4a 16.12.5 16.12.5a 16.12.5b 16.12.6 16.12.6a 16.12.7 16.12.8 16.12.9 16.12.10 16.12.10a 16.12.11 16.12.12 16.12.13 16.12.14 16.12.15 16.12.16 17.1.1 17.1.1a 17.1.1s 17.1.1t 17.1.2 17.1.3 17.2.1 17.2.1a 17.2.1r 17.2.1v 17.2.2 17.2.3 17.3.1 17.3.1a 17.3.1w 17.3.1x 17.3.1z 17.3.2 17.3.2a 17.3.3 17.3.3a 17.3.4 17.3.4a 17.3.4b 17.3.4c 17.3.5 17.3.5a 17.3.5b 17.3.6 17.3.7 17.3.8 17.3.8a 17.4.1 17.4.1a 17.4.1b 17.4.1c 17.4.2 17.4.2a 17.5.1 17.5.1a 17.6.1 17.6.1a 17.6.1x 17.6.1z 17.6.1z1 17.6.2 17.6.3 17.6.3a 17.6.4 17.6.5 17.6.5a 17.6.6 17.6.6a 17.6.7 17.6.8 17.6.8a 17.7.1 17.7.1a 17.7.1b 17.7.2 17.8.1 17.8.1a 17.9.1 17.9.1a 17.9.1w 17.9.1x 17.9.1x1 17.9.1y 17.9.1y1 17.9.2 17.9.2a 17.9.3 17.9.3a 17.9.4 17.9.4a 17.9.5 17.9.5a 17.9.5b 17.9.5c 17.9.5d 17.9.5e 17.9.5f 17.9.6 17.9.6a 17.9.7 17.9.7a 17.9.7b 17.9.8 17.9.9 17.10.1 17.10.1a 17.10.1b 17.11.1 17.11.1a 17.12.1 17.12.1a 17.12.1w 17.12.1x 17.12.1y 17.12.1z 17.12.1z1 17.12.1z2 17.12.1z3 17.12.1z4 17.12.1z5 17.12.1z6 17.12.2 17.12.2a 17.12.3 17.12.3a 17.12.4 17.12.4a 17.12.4b 17.12.5 17.12.5a 17.12.5b 17.12.5c 17.12.5d 17.12.6 17.12.6a 17.12.6b 17.12.7 17.12.7a 17.12.7b 17.13.1 17.13.1a 17.14.1 17.14.1a 17.15.1 17.15.1a 17.15.1b 17.15.1w 17.15.1x 17.15.1y 17.15.2 17.15.2a 17.15.2b 17.15.2c 17.15.3 17.15.3a 17.15.3b 17.15.4 17.15.4a 17.15.4b 17.15.4c 17.15.4d 17.15.4s1 17.15.5 17.15.5a 17.15.7 17.16.1 17.16.1a 17.17.1 17.18.1a 17.18.1w 17.18.1x 17.18.1y 17.18.1z 17.18.2 17.18.3 17.18.3a 26.1.1 26.1.1a |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | CVE Modified | CVE |
| Aug 12, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |