Missing Release of Resource after Effective Lifetime in Cisco IOS XE - CVE-2026-20124

 

Missing Release of Resource after Effective Lifetime in Cisco IOS XE - CVE-2026-20124

Published: August 6, 2026


Vulnerability identifier: #VU141043
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20124
CWE-ID: CWE-772
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper error handling in the Simple Network Management Protocol (SNMP) subsystem when parsing SNMP requests. A remote user can send a malformed SNMP request to cause a denial of service.

Successful exploitation causes the affected device to reload unexpectedly. The issue affects SNMP versions 1, 2c, and 3, and SNMP must be enabled on the device.


Affected software

Cisco IOS XE

How to mitigate CVE-2026-20124

Install security update from vendor's website.

Cisco IOS XE - addressed in versions 17.9.10, 17.12.7, 17.15.5, 17.18.3, 26.1.1, 26.2.1ea, 26.02.01ea1

External References

Related Security Bulletins