Cisco Changes IOS XE Fix Matrix for Seven CVEs
Cisco revised its IOS XE fix matrix on 2 October. Recheck your destination; no workaround exists.
| Train | Destination |
|---|---|
| 17.8 and earlier | Migrate to a fixed release |
| 17.9 | 17.9.10 |
| 17.12 | 17.12.8 |
| 17.15 | 17.15.6 |
| 17.18 | 17.18.4 or 17.18.4a |
| 26.1 | 26.1.2 |
Seven class-level identifiers, CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20272 and CVE-2026-20273, group multiple bugs. Scores are class maxima; injection reaches 9.8. Autonomous and controller deployments are affected regardless of configuration; Cisco reports no known malicious use.
Catalyst 3650/3850 switches on IOS XE 16.12 or earlier remain affected; no hardened 16.12 release is planned. Cisco’s future policy covers confirmed high-risk issues, not a full fix.
Source: Cisco advisory, published 5 August; advisory version 1.1 revised 2 October.
Related: separate IOS XR advisory.


