CVE-2026-20263
HIGH · CVSS 8.6 · EPSS 0.33% · CWE CWE-388
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.
CVE-2026-20263 is confirmed by Cisco as affecting 3 products, including Cisco IOS XE Software, Cisco IOS XE Catalyst SD-WAN, and Cisco Catalyst SD-WAN Controller, via 1 advisory (CVSS 8.6; EPSS 0.3%).
3 products with CSAF evidence