Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco IOS XE Software Security Hardening Release: August 2026

Cisco discovered several security weaknesses in its IOS XE software during internal testing. These issues are not known to be actively exploited in the wild. Cisco released upgraded software versions to harden security and fix these vulnerabilities. There are no workarounds, so upgrading is the recommended action to protect your systems.

QCS published 3/10/2026, 3:36:51 am ISTVendor disclosure 3/10/2026, 12:51:28 am ISTVerified 3/10/2026, 3:36:51 am ISTRevision 1

In plain language

What this advisory means

Cisco discovered several security weaknesses in its IOS XE software during internal testing. These issues are not known to be actively exploited in the wild. Cisco released upgraded software versions to harden security and fix these vulnerabilities. There are no workarounds, so upgrading is the recommended action to protect your systems.

Technical explanation

How the issue affects the environment

The Cisco IOS XE software underwent a comprehensive internal security audit, revealing multiple vulnerabilities spanning various Common Weakness Enumerations (CWEs), including improper access control (CWE-284), buffer overflows (CWE-119), resource lifetime mismanagement (CWE-664), incorrect calculations (CWE-682), insufficient control flow management (CWE-691), command injection risks (CWE-74), and input validation failures (CWE-20). Each issue has a corresponding CVE identifier, with severity ratings up to a CVSS 3.1 base score of 9.8. These vulnerabilities can allow unauthorized access, code execution, or denial of service. Cisco has issued fixed software versions starting from release 17.9.10 and later variants, addressing all identified vulnerabilities. No mitigation workarounds exist; upgrading is necessary.

Operational impact

Why teams should care

Organizations using Cisco IOS XE software could face critical security risks if these vulnerabilities are exploited, potentially leading to unauthorized system access, data compromise, or disruption of network services. Since no workarounds are available, failure to update to the fixed versions may expose networks to significant operational and security threats.

Immediate action

Cisco strongly recommends upgrading affected Cisco IOS XE software to one of the specified fixed releases to fully remediate the described vulnerabilities. Customers should consult Cisco's official resources and ensure device compatibility before upgrading. For releases 16.12 and earlier on Catalyst 3650/3850 switches, contact Cisco TAC or a representative for future fixes.

Affected and fixed releases

Affected versionsCisco IOS XE Release 17.8 and earlier, including 16.12 and earlier for Cisco Catalyst 3650 and 3850 Series Switches
Fixed versions17.9.10, 17.12.8, 17.15.6, 17.18.4, 17.18.4a, 26.1.2

Temporary risk reduction

There are no workarounds that mitigate these vulnerabilities. Applying the provided software updates is the only recommended mitigation step.

Evidence and validation checklist

  • Cisco PSIRT advisory published August 5, 2026, updated October 2, 2026
  • CVE identifiers assigned to grouped vulnerabilities
  • Internal security review and testing described by Cisco
  • Fixed software releases provided by Cisco
  • Lack of known public or malicious exploitation as stated by Cisco PSIRT

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source