Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3887 articles · 197514 vulns · 37/41 feeds (7d)
← Back to list
8.6
CVE-2026-20263
Cisco · Cisco IOS XE Software

Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability

Description

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.

Affected Products

VendorProductVersions
CiscoCisco IOS XE Software17.2.1a, 16.12.1y, 16.12.3s, 16.7.1b, 16.6.2, 16.6.5, 16.12.1w, 16.9.1d, 17.3.1, 16.9.4c, 16.7.1, 17.2.1, 16.6.8, 16.9.1b, 16.9.2s, 16.12.4, 16.12.3a, 17.1.1s, 16.11.1a, 16.7.2, 16.11.1b, 16.9.1s, 16.9.3h, 16.9.1c, 16.6.5a, 16.6.3, 16.10.1f, 17.2.1v, 16.8.1e, 16.9.3a, 16.12.1a, 16.12.1x, 16.6.4s, 16.10.1c, 16.12.3, 16.11.2, 16.6.5b, 16.12.2s, 16.10.1b, 16.7.3, 16.6.7, 16.9.6, 16.9.2, 16.10.1, 16.12.1t, 16.9.1, 16.8.1a, 16.9.3s, 16.6.7a, 16.12.2, 16.11.1, 16.9.3, 16.11.1s, 16.12.1, 17.1.1, 17.1.2, 16.10.1d, 17.1.1t, 16.9.4, 16.8.3, 16.12.2t, 16.9.5, 16.8.1s, 16.10.1e, 16.8.2, 16.6.4, 16.8.1b, 16.10.1a, 16.12.1z, 16.8.1c, 16.9.1a, 16.9.5f, 16.6.4a, 16.10.1g, 16.8.1, 16.6.6, 16.9.2a, 16.8.1d, 16.10.3, 16.7.1a, 16.11.1c, 16.10.1s, 17.2.1r, 17.1.1a, 16.10.2, 16.12.2a, 16.12.1c, 16.12.1s, 16.7.4, 17.2.2, 16.9.8, 16.9.7, 17.1.3, 17.3.1a, 17.3.2a, 16.12.5, 17.3.1w, 17.3.2, 17.4.1, 16.12.4a, 17.4.1a, 17.3.1x, 17.3.3, 16.6.9, 17.2.3, 17.5.1, 16.12.1z1, 16.12.5a, 17.4.1b, 17.3.1z, 16.12.5b, 17.4.2, 17.3.3a, 17.3.5, 17.3.4, 17.5.1a, 16.12.6, 17.6.1, 16.12.1z2, 16.6.10, 17.3.4a, 17.6.1a, 17.7.1, 17.6.1x, 17.6.2, 16.12.6a, 17.3.4c, 17.4.2a, 17.3.4b, 17.7.1a, 16.12.7, 17.8.1a, 17.6.3a, 17.6.3, 17.7.2, 17.7.1b, 17.9.1w, 17.3.5a, 17.6.1z, 16.12.8, 17.8.1, 17.9.1, 17.6.4, 17.3.5b, 17.9.1a, 17.3.6, 17.10.1, 16.9.8a, 17.6.1z1, 17.10.1a, 17.9.2, 17.6.5, 17.9.1x, 17.9.1y, 16.9.8b, 17.3.7, 17.9.2a, 17.9.3, 16.12.9, 17.11.1, 17.10.1b, 17.6.6, 17.9.1x1, 17.11.1a, 17.9.3a, 17.12.1, 17.3.8, 17.9.4, 16.12.10, 17.12.1w, 17.9.1y1, 17.12.1a, 17.9.5, 17.13.1, 17.12.1x, 17.12.2, 17.14.1, 17.9.4a, 17.3.8a, 17.6.6a, 17.6.5a, 17.6.7, 16.12.10a, 17.15.1, 17.13.1a, 17.12.2a, 16.12.11, 17.12.3, 17.12.1y, 17.12.1z, 17.9.5a, 17.14.1a, 17.9.5b, 17.6.8, 16.12.12, 17.12.4, 17.9.6, 17.17.1, 17.16.1, 17.15.1w, 17.12.3a, 17.9.5c, 17.15.1a, 17.12.1z1, 17.15.2, 17.15.1b, 17.9.5d, 17.15.1x, 17.9.6a, 17.12.1z2, 17.6.8a, 17.16.1a, 16.12.13, 17.15.3, 17.9.7, 17.12.5, 17.15.1y, 17.9.5e, 17.12.4a, 17.15.2a, 17.15.2c, 17.15.2b, 17.12.1z3, 17.9.5f, 17.12.4b, 17.12.5a, 17.18.1, 17.12.6, 17.12.1z4, 17.9.8, 17.9.7a, 17.15.3a, 17.15.4, 17.12.5b, 17.15.3b, 16.12.14, 17.18.1z, 17.9.7b, 17.12.5c, 26.1.1, 17.18.1a, 17.15.4a, 17.18.2, 17.18.1w, 17.15.4b, 17.12.6a, 17.12.7, 17.15.4c, 17.9.9, 17.12.5d, 16.12.15, 17.15.4s1, 17.15.5, 17.12.1z5, 17.18.1x, 17.12.1z6, 17.15.4d, 17.12.6b, 17.4.1c, 17.15.5a, 17.18.1y, 17.12.7a, 17.18.3, 17.12.7b, 17.18.3a, 26.1.1a, 26.2.1ea

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cisios xecert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd

Related News (4 articles)

Tier B
BSI Advisories19d ago
[NEU] [hoch] Cisco IOS XE: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR20d ago
Multiples vulnérabilités dans les produits Cisco (06 août 2026)
→ No new info (linked only)
Tier C
VulDB20d ago
CVE-2026-20263 | Cisco IOS XE Software up to 26.2.1ea BEEP denial of service
→ No new info (linked only)
Tier A
Cisco Security20d ago
Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability
→ No new info (linked only)
CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-388
PublishedAug 5, 2026
Last enriched20d ago
Trending Score7
Source articles4
Independent4
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20338
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 25
HIGHCVE-2026-20337
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 25
HIGHCVE-2026-20320
CVE-2026-20320: A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote
Trending: 24
MEDIUMCVE-2026-20232
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
Trending: 17
MEDIUMCVE-2026-20302
Cisco RoomOS Stack Overflow Vulnerability
Trending: 13

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026