← Browse

CVE-2026-20268

Medium

Elevated severity or exploit probability.

CVSS base
8.6 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
0.3%
21.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-119
Published 2026-08-05 · modified 2026-08-14

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredNNone
User InteractionNNone
ScopeCChanged
ConfidentialityNNone
IntegrityNNone
AvailabilityHHigh

Timeline

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.

Affected

cisco

References

Official: NVD · CVE.org