๐Ÿ” CVE Alert

CVE-2026-20301

HIGH 8.6

Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.

CWE CWE-606
Vendor cisco
Product cisco ios xe software
Ecosystems
Industries
NetworkingTelecommunications
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for cisco cisco ios xe software

Be the first to know when new high vulnerabilities affecting cisco cisco ios xe software are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Cisco / Cisco IOS XE Software
17.2.1a 16.12.1y 16.12.3s 16.7.1b 16.6.2 16.6.5 16.12.1w 16.9.1d 17.3.1 16.9.4c 16.7.1 17.2.1 16.6.8 16.9.1b 16.9.2s 16.12.4 16.12.3a 17.1.1s 16.11.1a 16.7.2 16.11.1b 16.9.1s 16.9.3h 16.9.1c 16.6.5a 16.6.3 16.10.1f 17.2.1v 16.8.1e 16.9.3a 16.12.1a 16.12.1x 3.16.10aS 16.6.4s 16.10.1c 16.12.3 16.11.2 16.6.5b 16.12.2s 16.10.1b 16.7.3 16.6.7 16.9.6 16.9.2 16.10.1 16.12.1t 16.9.1 16.8.1a 3.18.8aSP 16.9.3s 16.6.7a 16.12.2 16.11.1 16.9.3 16.11.1s 16.12.1 17.1.1 17.1.2 16.10.1d 17.1.1t 16.9.4 16.8.3 16.12.2t 16.9.5 16.8.1s 16.10.1e 16.8.2 16.6.4 16.8.1b 16.10.1a 16.12.1z 16.8.1c 16.9.1a 16.9.5f 16.6.4a 16.10.1g 16.8.1 16.6.6 16.9.2a 16.8.1d 16.10.3 16.7.1a 16.11.1c 16.10.1s 17.2.1r 17.1.1a 16.10.2 16.12.2a 16.12.1c 16.12.1s 16.7.4 3.18.9SP 17.2.2 3.11.3E 16.9.8 16.9.7 17.1.3 17.3.1a 3.11.4E 17.3.2a 16.12.5 17.3.1w 17.3.2 3.11.3aE 17.4.1 16.12.4a 17.4.1a 3.16.10bS 17.3.1x 17.3.3 16.6.9 17.2.3 17.5.1 16.12.1z1 16.12.5a 17.4.1b 17.3.1z 16.12.5b 17.4.2 17.3.3a 3.11.5E 17.3.5 17.3.4 17.5.1a 16.12.6 17.6.1 16.12.1z2 16.6.10 17.3.4a 17.6.1a 3.8.10cE 17.7.1 17.6.1x 17.6.2 16.12.6a 17.3.4c 17.4.2a 17.3.4b 17.7.1a 16.12.7 17.8.1a 17.6.3a 17.6.3 17.7.2 17.7.1b 17.9.1w 17.3.5a 17.6.1z 3.8.10dE 16.12.8 17.8.1 17.9.1 3.11.6E 17.6.4 3.11.7E 17.3.5b 17.9.1a 17.3.6 17.10.1 3.11.8E 16.9.8a 17.6.1z1 17.10.1a 17.9.2 17.6.5 17.9.1x 17.9.1y 16.9.8b 17.3.7 17.9.2a 17.9.3 16.12.9 17.11.1 17.10.1b 17.6.6 17.9.1x1 17.11.1a 17.9.3a 17.12.1 17.3.8 17.9.4 16.12.10 17.12.1w 17.9.1y1 17.12.1a 3.11.9E 17.9.5 17.13.1 17.12.1x 17.12.2 17.14.1 17.9.4a 17.3.8a 17.6.6a 17.6.5a 17.6.7 16.12.10a 17.15.1 17.13.1a 17.12.2a 16.12.11 17.12.3 17.12.1y 3.11.10E 17.12.1z 17.9.5a 17.14.1a 17.9.5b 17.6.8 16.12.12 17.12.4 17.9.6 17.17.1 17.16.1 17.15.1w 17.12.3a 3.11.11E 17.9.5c 17.15.1a 17.12.1z1 17.15.2 17.15.1b 17.9.5d 17.15.1x 17.9.6a 17.12.1z2 17.6.8a 17.16.1a 16.12.13 17.15.3 17.9.7 17.12.5 17.15.1y 17.9.5e 17.12.4a 17.15.2a 17.15.2c 17.15.2b 17.12.1z3 17.9.5f 17.12.4b 3.11.12E 17.12.5a 17.18.1 17.12.6 17.12.1z4 17.9.8 17.9.7a 17.15.3a 17.15.4 3.11.13E 17.12.5b 17.15.3b 16.12.14 17.18.1z 17.9.7b 17.12.5c 26.1.1 17.18.1a 17.15.4a 17.18.2 17.18.1w 17.15.4b 17.12.6a 17.12.7 17.15.4c 17.9.9 17.12.5d 16.12.15 17.15.4s1 17.15.5 17.12.1z5 17.18.1x 17.12.1z6 17.15.4d 17.12.6b 17.4.1c 3.11.14E 17.15.5a 17.18.1y 17.12.7a 17.18.3 17.12.7b 17.18.3a 26.1.1a 26.2.1ea 16.12.16
Cisco / IOS
15.2(7)E7 15.2(8)E3 15.7(3)M10 15.8(3)M9 15.9(3)M7 15.2(7)E8 15.2(8)E4 15.9(3)M7a 15.2(2)E10c 15.2(4)E10d 15.9(3)M6a 15.9(3)M6b 15.5(1)SY10 15.5(1)SY11 15.2(6)E1a 15.4(1)SY4 15.5(1)SY1 15.2(2)E8 15.2(6)E1 15.7(3)M2 15.2(4)E6 15.2(1)SY6 15.2(4)EA7 15.2(6)E1s 15.7(3)M3 15.8(3)M 15.2(1)SY7 15.2(4)EA8 15.8(3)M0a 15.2(2)E9 15.2(6)E2 15.5(1)SY2 15.2(4)E7 15.2(6)E2a 15.2(2)E9a 15.8(3)M0b 15.2(6)E2b 15.8(3)M1 15.8(3)M1a 15.7(3)M4 15.2(1)SY8 15.2(4)E8 15.5(1)SY3 15.2(7)E 15.7(3)M4a 15.8(3)M2 15.2(7)E0a 15.8(3)M2a 15.7(3)M4b 15.2(2)E10 15.2(7)E0s 15.2(4)EA9 15.2(7)E0b 15.2(6)E3 15.9(3)M 15.8(3)M3 15.5(1)SY4 15.7(3)M5 15.2(2)E10a 15.2(4)E9 15.2(7)E1 15.8(3)M3b 15.9(3)M0a 15.2(7)E1a 15.2(4)E10 15.5(1)SY5 15.2(4)EA9a 15.9(3)M1 15.8(3)M4 15.7(3)M6 15.2(7)E2 15.5(1)SY6 15.2(7)E3 15.8(3)M5 15.7(3)M7 15.9(3)M2 15.2(7)E2b 15.9(3)M2a 15.2(4)E10a 15.2(7)E4 15.5(1)SY7 15.2(4)E10b 15.2(7)E3k 15.2(8)E 15.9(3)M3 15.8(3)M6 15.7(3)M8 15.8(3)M7 15.5(1)SY8 15.2(7)E5 15.2(8)E1 15.9(3)M4 15.2(8)E2 15.2(4)E10c 15.7(3)M9 15.2(2)E10b 15.2(7)E6 15.9(3)M4a 15.5(1)SY9 15.9(3)M5 15.8(3)M8 15.9(3)M6 15.9(3)M9 15.5(1)SY13 15.9(3)M8b 15.2(7)E9 15.5(1)SY12 15.7(3)M10a 15.9(3)M8 15.9(3)M8a 15.2(8)E5 15.2(7)E10 15.7(3)M10b 15.9(3)M3a 15.8(3)M3a 15.9(3)M3b 15.6(2)SP7 15.6(2)SP5 15.6(2)SP8 15.6(2)SP6 15.6(2)SP4 15.6(2)SP9 15.6(2)SP8a 15.9(3)M9a 15.2(8)E6 15.9(3)M10 15.2(7)E11 15.5(1)SY14 15.2(8)E7 15.2(4)E10e 15.9(3)M11 15.2(7)E12 15.5(1)SY15 15.2(8)E8 15.5(1)SY16 15.2(7)E13 15.9(3)M12 15.5(1)SY17 15.2(7)E14 15.9(3)M13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sec.cloudapps.cisco.com: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t