CVE-2026-20263: Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20263?
The severity of CVE-2026-20263 is high, with a CVSS score of 8.6.
What is the risk associated with CVE-2026-20263?
CVE-2026-20263 has a risk rating of 49, indicating significant potential impact.
How do I fix CVE-2026-20263?
To mitigate CVE-2026-20263, ensure that Cisco IOS XE Software is updated to the latest patched version.
What type of attack can CVE-2026-20263 enable?
CVE-2026-20263 can allow an unauthenticated, remote attacker to execute a denial of service (DoS) attack on the affected device.
Which software is affected by CVE-2026-20263?
CVE-2026-20263 affects Cisco IOS XE Software that utilizes the Blocks Extensible Exchange Protocol (BEEP) feature.