CVE-2026-20269
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS probability
- 0.28%
- CWE
- CWE-664
- Published
- 2026-08-05
- Last modified
- 2026-08-14
Affected products
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
Weakness type
Related vulnerabilities
- CVE-2026-86203 — PocketMine-MP before 5.39.2 Item Duplication via Despawn State
- CVE-2026-20274 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-79289 — Improper control of a resource through its lifetime in Workers in Google Chrome prior to...
- CVE-2026-18549 — @fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit
- CVE-2026-19380 — Mullvad wireguard.sys IOCTL AdapterState reference count
- CVE-2026-20158 — Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities
- CVE-2025-34226 — OpenPLC Runtime v3 Persistent DoS
- CVE-2025-54621 — Iterator failure issue in the WantAgent module....