Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 2 advisories

CVE-2026-20301

CVE-2026-20301: 2 tracked advisory records across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

2 advisories
  • Advisory severityHigh8.6

    High [CVE-2026-20301] Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability

    cisco-sa-ios-xmcp-thbAr34tSource published Source updated

    A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.…

    Affected products in this advisory
    • IOS XE Software
    Source-reported affected versions
    • Scope: This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS Software or IOS XE Software and have the XMCP Server feature enabled.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.
    Workarounds
    • There are no workarounds that address this vulnerability. However, as a mitigation, administrators may configure an access control allow list to allow only clients that match the specified access list to connect. All other clients will be denied. In the following example configuration, only host 192.168.1.1 is allowed to connect.
    • service-routing xmcp listen
    • allow-list ipv4 XMCPClientListIPv4
    • client username test_xmcp password

    3 more entries in the full advisory.

  • Advisory severityHigh

    High [CVE-2026-20028 +21] Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

    cisco-sa-notice-L4XfJg8SSource published Source updated

    This bulletin covers 22 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20312 CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273 Critical 9.8 Cisco Integrated Management Controller Argument Injection Vulnerabilities CVE-2026-20200 CVE-2026-20288 High 8.8 Cisco IOS Software and IOS XE Software Extensible…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst SD-WAN Integrated Management Controller (IMC) IOS Software IOS XE Software RoomOS Terminal Services Agent To fully remediate vulnerabilities to be disclosed on August 5, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery