Answer in brief
CVE-2026-20272 records a Unknown severity vulnerability in Cisco IOS XE Software Security Hardening Release. The current sources do not mark it as known exploited. The current feed maps Cisco/Cisco IOS XE Software (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Cisco/Cisco IOS XE Software (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco IOS XE Softwaregeneric | 17.2.1a || 16.12.1y || 16.12.3s || 16.7.1b || 16.6.2 || 16.6.5 || 16.12.1w || 16.9.1d || 17.3.1 || 16.9.4c || 16.7.1 || 17.2.1 || 16.6.8 || 16.9.1b || 16.9.2s || 16.12.4 || 16.12.3a || 17.1.1s || 16.11.1a || 16.7.2 || 16.11.1b || 16.9.1s || 16.9.3h || 16.9.1c || 16.6.5a || 16.6.3 || 16.10.1f || 17.2.1v || 16.8.1e || 16.9.3a || 16.12.1a || 16.12.1x || 16.6.4s || 16.10.1c || 16.12.3 || 16.11.2 || 16.6.5b || 16.12.2s || 16.10.1b || 16.7.3 || 16.6.7 || 16.9.6 || 16.9.2 || 16.10.1 || 16.12.1t || 16.9.1 || 16.8.1a || 16.9.3s || 16.6.7a || 16.12.2 || 16.11.1 || 16.9.3 || 16.11.1s || 16.12.1 || 17.1.1 || 17.1.2 || 16.10.1d || 17.1.1t || 16.9.4 || 16.8.3 || 16.12.2t || 16.9.5 || 16.8.1s || 16.10.1e || 16.8.2 || 16.6.4 || 16.8.1b || 16.10.1a || 16.12.1z || 16.8.1c || 16.9.1a || 16.9.5f || 16.6.4a || 16.10.1g || 16.8.1 || 16.6.6 || 16.9.2a || 16.8.1d || 16.10.3 || 16.7.1a || 16.11.1c || 16.10.1s || 17.2.1r || 17.1.1a || 16.10.2 || 16.12.2a || 16.12.1c || 16.12.1s || 16.7.4 || 17.2.2 || 16.9.8 || 16.9.7 || 17.1.3 || 17.3.1a || 17.3.2a || 16.12.5 || 17.3.1w || 17.3.2 || 17.4.1 || 16.12.4a || 17.4.1a || 17.3.1x || 17.3.3 || 16.6.9 || 17.2.3 || 17.5.1 || 16.12.1z1 || 16.12.5a || 17.4.1b || 17.3.1z || 16.12.5b || 17.4.2 || 17.3.3a || 17.3.5 || 17.3.4 || 17.5.1a || 16.12.6 || 17.6.1 || 16.12.1z2 || 16.6.10 || 17.3.4a || 17.6.1a || 17.7.1 || 17.6.1x || 17.6.2 || 16.12.6a || 17.3.4c || 17.4.2a || 17.3.4b || 17.7.1a || 16.12.7 || 17.8.1a || 17.6.3a || 17.6.3 || 17.7.2 || 17.7.1b || 17.9.1w || 17.3.5a || 17.6.1z || 16.12.8 || 17.8.1 || 17.9.1 || 17.6.4 || 17.3.5b || 17.9.1a || 17.3.6 || 17.10.1 || 16.9.8a || 17.6.1z1 || 17.10.1a || 17.9.2 || 17.6.5 || 17.9.1x || 17.9.1y || 16.9.8b || 17.3.7 || 17.9.2a || 17.9.3 || 16.12.9 || 17.11.1 || 17.10.1b || 17.6.6 || 17.9.1x1 || 17.11.1a || 17.9.3a || 17.12.1 || 17.3.8 || 17.9.4 || 16.12.10 || 17.12.1w || 17.9.1y1 || 17.12.1a || 17.9.5 || 17.13.1 || 17.12.1x || 17.12.2 || 17.14.1 || 17.9.4a || 17.3.8a || 17.6.6a || 17.6.5a || 17.6.7 || 16.12.10a || 17.15.1 || 17.13.1a || 17.12.2a || 16.12.11 || 17.12.3 || 17.12.1y || 17.12.1z || 17.9.5a || 17.14.1a || 17.9.5b || 17.6.8 || 16.12.12 || 17.12.4 || 17.9.6 || 17.17.1 || 17.16.1 || 17.15.1w || 17.12.3a || 17.9.5c || 17.15.1a || 17.12.1z1 || 17.15.2 || 17.15.1b || 17.9.5d || 17.15.1x || 17.9.6a || 17.12.1z2 || 17.6.8a || 17.16.1a || 16.12.13 || 17.15.3 || 17.9.7 || 17.12.5 || 17.15.1y || 17.9.5e || 17.12.4a || 17.15.2a || 17.15.2c || 17.15.2b || 17.12.1z3 || 17.9.5f || 17.12.4b || 17.12.5a || 17.18.1 || 17.12.6 || 17.12.1z4 || 17.9.8 || 17.9.7a || 17.15.3a || 17.15.4 || 17.12.5b || 17.15.3b || 16.12.14 || 17.18.1z || 17.9.7b || 17.12.5c || 26.1.1 || 17.18.1a || 17.15.4a || 17.18.2 || 17.18.1w || 17.15.4b || 17.12.6a || 17.12.7 || 17.15.4c || 17.9.9 || 17.12.5d || 16.12.15 || 17.15.4s1 || 17.15.5 || 17.12.1z5 || 17.18.1x || 17.12.1z6 || 17.15.4d || 17.12.6b || 17.4.1c || 17.15.5a || 17.18.1y || 17.12.7a || 17.18.3 || 17.12.7b || 17.18.3a || 26.1.1a || 17.15.7 || 16.12.16 | Not reported |
Published upstream
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-20272 records a Unknown severity vulnerability in Cisco IOS XE Software Security Hardening Release. The current sources do not mark it as known exploited. The current feed maps Cisco/Cisco IOS XE Software (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Cisco/Cisco IOS XE Software (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco IOS XE Softwaregeneric | 17.2.1a || 16.12.1y || 16.12.3s || 16.7.1b || 16.6.2 || 16.6.5 || 16.12.1w || 16.9.1d || 17.3.1 || 16.9.4c || 16.7.1 || 17.2.1 || 16.6.8 || 16.9.1b || 16.9.2s || 16.12.4 || 16.12.3a || 17.1.1s || 16.11.1a || 16.7.2 || 16.11.1b || 16.9.1s || 16.9.3h || 16.9.1c || 16.6.5a || 16.6.3 || 16.10.1f || 17.2.1v || 16.8.1e || 16.9.3a || 16.12.1a || 16.12.1x || 16.6.4s || 16.10.1c || 16.12.3 || 16.11.2 || 16.6.5b || 16.12.2s || 16.10.1b || 16.7.3 || 16.6.7 || 16.9.6 || 16.9.2 || 16.10.1 || 16.12.1t || 16.9.1 || 16.8.1a || 16.9.3s || 16.6.7a || 16.12.2 || 16.11.1 || 16.9.3 || 16.11.1s || 16.12.1 || 17.1.1 || 17.1.2 || 16.10.1d || 17.1.1t || 16.9.4 || 16.8.3 || 16.12.2t || 16.9.5 || 16.8.1s || 16.10.1e || 16.8.2 || 16.6.4 || 16.8.1b || 16.10.1a || 16.12.1z || 16.8.1c || 16.9.1a || 16.9.5f || 16.6.4a || 16.10.1g || 16.8.1 || 16.6.6 || 16.9.2a || 16.8.1d || 16.10.3 || 16.7.1a || 16.11.1c || 16.10.1s || 17.2.1r || 17.1.1a || 16.10.2 || 16.12.2a || 16.12.1c || 16.12.1s || 16.7.4 || 17.2.2 || 16.9.8 || 16.9.7 || 17.1.3 || 17.3.1a || 17.3.2a || 16.12.5 || 17.3.1w || 17.3.2 || 17.4.1 || 16.12.4a || 17.4.1a || 17.3.1x || 17.3.3 || 16.6.9 || 17.2.3 || 17.5.1 || 16.12.1z1 || 16.12.5a || 17.4.1b || 17.3.1z || 16.12.5b || 17.4.2 || 17.3.3a || 17.3.5 || 17.3.4 || 17.5.1a || 16.12.6 || 17.6.1 || 16.12.1z2 || 16.6.10 || 17.3.4a || 17.6.1a || 17.7.1 || 17.6.1x || 17.6.2 || 16.12.6a || 17.3.4c || 17.4.2a || 17.3.4b || 17.7.1a || 16.12.7 || 17.8.1a || 17.6.3a || 17.6.3 || 17.7.2 || 17.7.1b || 17.9.1w || 17.3.5a || 17.6.1z || 16.12.8 || 17.8.1 || 17.9.1 || 17.6.4 || 17.3.5b || 17.9.1a || 17.3.6 || 17.10.1 || 16.9.8a || 17.6.1z1 || 17.10.1a || 17.9.2 || 17.6.5 || 17.9.1x || 17.9.1y || 16.9.8b || 17.3.7 || 17.9.2a || 17.9.3 || 16.12.9 || 17.11.1 || 17.10.1b || 17.6.6 || 17.9.1x1 || 17.11.1a || 17.9.3a || 17.12.1 || 17.3.8 || 17.9.4 || 16.12.10 || 17.12.1w || 17.9.1y1 || 17.12.1a || 17.9.5 || 17.13.1 || 17.12.1x || 17.12.2 || 17.14.1 || 17.9.4a || 17.3.8a || 17.6.6a || 17.6.5a || 17.6.7 || 16.12.10a || 17.15.1 || 17.13.1a || 17.12.2a || 16.12.11 || 17.12.3 || 17.12.1y || 17.12.1z || 17.9.5a || 17.14.1a || 17.9.5b || 17.6.8 || 16.12.12 || 17.12.4 || 17.9.6 || 17.17.1 || 17.16.1 || 17.15.1w || 17.12.3a || 17.9.5c || 17.15.1a || 17.12.1z1 || 17.15.2 || 17.15.1b || 17.9.5d || 17.15.1x || 17.9.6a || 17.12.1z2 || 17.6.8a || 17.16.1a || 16.12.13 || 17.15.3 || 17.9.7 || 17.12.5 || 17.15.1y || 17.9.5e || 17.12.4a || 17.15.2a || 17.15.2c || 17.15.2b || 17.12.1z3 || 17.9.5f || 17.12.4b || 17.12.5a || 17.18.1 || 17.12.6 || 17.12.1z4 || 17.9.8 || 17.9.7a || 17.15.3a || 17.15.4 || 17.12.5b || 17.15.3b || 16.12.14 || 17.18.1z || 17.9.7b || 17.12.5c || 26.1.1 || 17.18.1a || 17.15.4a || 17.18.2 || 17.18.1w || 17.15.4b || 17.12.6a || 17.12.7 || 17.15.4c || 17.9.9 || 17.12.5d || 16.12.15 || 17.15.4s1 || 17.15.5 || 17.12.1z5 || 17.18.1x || 17.12.1z6 || 17.15.4d || 17.12.6b || 17.4.1c || 17.15.5a || 17.18.1y || 17.12.7a || 17.18.3 || 17.12.7b || 17.18.3a || 26.1.1a || 17.15.7 || 16.12.16 | Not reported |
Published upstream
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
Quoted source text, attributed separately from HOL analysis.