#VU123906 Improper cleanup on thrown exception in Cisco IOS XR - CVE-2026-20118
Published: March 12, 2026
Cisco IOS XR
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to an error when handling Egress Packet Network Interface (EPNI) Aligner interrupt. A remote attacker can send a continuous flow of crafted packets to an interface of the affected device and prevent traffic from traversing the interface.