CVE-2026-20308
MEDIUM · CVSS 4.3 · EPSS 0.32% · CWE CWE-269
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.
CVE-2026-20308 is confirmed by Cisco as affecting 7 products, including Cisco Aironet Access Point Software (IOS XE Controller), Cisco IOS XE Catalyst SD-WAN, and Cisco IOS XE Software, and 4 more, via 1 advisory (CVSS 4.3; EPSS 0.3%).
7 products with CSAF evidence