# Cisco IOS XE patches multiple security bypass flaws

Published: 2026-08-25 · Severity: routine · Sectors: technology, telecommunications, infrastructure
Canonical: https://vorant.io/reports/72c6c05a-3493-5d00-b2a7-59d05fb04fae/cisco-ios-xe-patches-multiple-security-bypass-flaws

> ANSSI advisory details seven Cisco IOS XE vulnerabilities allowing security policy bypass and unspecified issues, fixed in updated releases.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory summarizing a Cisco security bulletin covering seven vulnerabilities (CVE-2026-20267 through CVE-2026-20273) in Cisco IOS XE Software. The flaws allow an attacker to bypass security policy controls and trigger other unspecified security issues; Cisco's advisory does not detail the exact mechanisms or impact beyond these categories.

Affected versions span multiple IOS XE branches: 17.9.x before 17.9.10, 17.12.x before 17.12.8, 17.15.x before 17.15.6, 17.18 before 17.18.4/17.18.4a, and 26.1.x before 26.1.2. Cisco has released patched versions addressing these issues, and organizations running affected IOS XE releases should apply the vendor fixes referenced in the Cisco security advisory (cisco-sa-hardening-iosxe-V8NMuMZJ). No indication of active exploitation is provided in this advisory; it is a standard vendor patch notification relayed by ANSSI.

Defenders operating Cisco IOS XE devices should inventory affected versions and prioritize patching per standard vulnerability management processes, particularly given the network infrastructure role these devices typically play.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20272, CVE-2026-20273

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1077

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/72c6c05a-3493-5d00-b2a7-59d05fb04fae/cisco-ios-xe-patches-multiple-security-bypass-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
