CVE-2026-20301

Cisco · IOS and IOS XE Software

A vulnerability in the Extensible Messaging Client Protocol of Cisco IOS and IOS XE Software allows an unauthenticated remote attacker to cause a denial of service on an affected device.

Executive summary

An unauthenticated, remote denial of service vulnerability in Cisco IOS and IOS XE Software poses a high risk to network availability.

Vulnerability

This vulnerability, identified as CWE-606 (Unchecked Input for Loop Condition), exists within the Extensible Messaging Client Protocol. An unauthenticated remote attacker can trigger this flaw to crash the device, leading to a denial of service.

Business impact

Successful exploitation results in the loss of device availability, which can disrupt critical network infrastructure and communication services. Given the CVSS score of 8.6, the potential for significant operational downtime is high, necessitating urgent attention to maintain service level agreements and network stability.

Remediation

Immediate Action: Update the affected Cisco IOS and IOS XE software to the latest versions recommended in the official Cisco security advisory.

Proactive Monitoring: Monitor network device logs for unusual spikes in traffic directed at the Extensible Messaging Client Protocol or unexpected device reboots.

Compensating Controls: Restrict access to the management interface and relevant protocols to trusted management subnets using Access Control Lists (ACLs) to mitigate unauthorized attempts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this issue demands immediate remediation. Security teams should prioritize patching affected Cisco devices to prevent potential service disruptions. If immediate patching is not feasible, apply restrictive ACLs to limit exposure to the impacted protocol.