Buffer over-read in Cisco IOS XE - CVE-2026-20311
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to insufficient error handling in the web-based management interface when authenticating with a malformed certificate. A remote user can authenticate with a malformed certificate to cause a denial of service.
Only devices with the HTTP Server feature and PIV-based authentication enabled are vulnerable. A successful exploit causes the affected device to reload.