CVE-2026-20263 with a CVSS score of 8.6 is a denial of service vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software, which could allow an unauthenticated, remote attacker to cause a device to reload unexpectedly, resulting in a denial of service condition. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request, and it affects Cisco IOS XE Software if the BEEP feature is configured. The affected component is the BEEP feature itself, which is used for NETCONF over BEEP sessions. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device, and a successful exploit could allow the attacker to cause a denial of service condition without requiring any privileges or user interaction. This vulnerability has significant business impact as it can lead to unexpected device reloads, resulting in downtime and potential data loss. The affected versions are not explicitly stated in the advisory, but the vulnerability affects Cisco IOS XE Software if the BEEP feature is configured.
We recommend you to update Cisco IOS XE Software to given version link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Blocks%20Extensible%20Exchange%20Protocol%20Denial%20of%20Service%20Vulnerability%26vs_k=1[/subscribe_to_unlock_form]
CVE-2026-20263 with a CVSS score of 8.6 is a denial of service vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software, which could allow an unauthenticated, remote attacker to cause a device to reload unexpectedly, resulting in a denial of service condition. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request, and it affects Cisco IOS XE Software if the BEEP feature is configured. The affected component is the BEEP feature itself, which is used for NETCONF over BEEP sessions. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device, and a successful exploit could allow the attacker to cause a denial of service condition without requiring any privileges or user interaction. This vulnerability has significant business impact as it can lead to unexpected device reloads, resulting in downtime and potential data loss. The affected versions are not explicitly stated in the advisory, but the vulnerability affects Cisco IOS XE Software if the BEEP feature is configured.
We recommend you to update Cisco IOS XE Software to given version link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Blocks%20Extensible%20Exchange%20Protocol%20Denial%20of%20Service%20Vulnerability%26vs_k=1[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]