CVE-2026-20124High· 7.7▾ TwilightA vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.4%
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.
ios_xe = 3.13.9sios_xe = 3.13.10sios_xe = 3.16.6bsios_xe = 3.16.7asios_xe = 3.16.7bsios_xe = 3.16.7sios_xe = 3.16.8sios_xe = 3.16.9sios_xe = 3.16.10asios_xe = 3.16.10bsios_xe = 3.16.10sios_xe = 3.18.3aspios_xe = 3.18.3bspios_xe = 3.18.3spios_xe = 3.18.4sios_xe = 3.18.4spios_xe = 3.18.5spios_xe = 3.18.6spios_xe = 3.18.7spios_xe = 3.18.8aspios_xe = 3.18.9spios_xe = 16.6.2ios_xe = 16.6.3ios_xe = 16.6.4ios_xe = 16.6.4aios_xe = 16.6.4sios_xe = 16.6.5ios_xe = 16.6.5aios_xe = 16.6.5bios_xe = 16.6.6ios_xe = 16.6.7ios_xe = 16.6.7aios_xe = 16.6.8ios_xe = 16.6.9ios_xe = 16.6.10ios_xe = 16.7.1ios_xe = 16.7.1aios_xe = 16.7.1bios_xe = 16.7.2ios_xe = 16.7.3ios_xe = 16.7.4ios_xe = 16.8.1ios_xe = 16.8.1aios_xe = 16.8.1bios_xe = 16.8.1cios_xe = 16.8.1dios_xe = 16.8.1eios_xe = 16.8.1sios_xe = 16.8.2ios_xe = 16.8.3ios_xe = 16.9.1ios_xe = 16.9.1aios_xe = 16.9.1bios_xe = 16.9.1cios_xe = 16.9.1dios_xe = 16.9.1sios_xe = 16.9.2ios_xe = 16.9.2aios_xe = 16.9.2sios_xe = 16.9.3ios_xe = 16.9.3aios_xe = 16.9.3hios_xe = 16.9.3sios_xe = 16.9.4ios_xe = 16.9.4cios_xe = 16.9.5ios_xe = 16.9.5fios_xe = 16.9.6ios_xe = 16.9.7ios_xe = 16.9.8ios_xe = 16.9.8aios_xe = 16.9.8bios_xe = 16.10.1ios_xe = 16.10.1aios_xe = 16.10.1bios_xe = 16.10.1cios_xe = 16.10.1dios_xe = 16.10.1eios_xe = 16.10.1fios_xe = 16.10.1gios_xe = 16.10.1sios_xe = 16.10.2ios_xe = 16.10.3ios_xe = 16.11.1ios_xe = 16.11.1aios_xe = 16.11.1bios_xe = 16.11.1cios_xe = 16.11.1sios_xe = 16.11.2ios_xe = 16.12.1ios_xe = 16.12.1aios_xe = 16.12.1cios_xe = 16.12.1sios_xe = 16.12.1tios_xe = 16.12.1wios_xe = 16.12.1xios_xe = 16.12.1yios_xe = 16.12.1zios_xe = 16.12.1z1ios_xe = 16.12.1z2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-20311High· 7.4A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traff…
CVE-2025-20312High· 7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability i…
CVE-2025-20313Medium· 6.7Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and brea…
CVE-2026-20250High· 8.6A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series dev…
CVE-2026-20272Critical· 9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review
CVE-2026-20271High· 8.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review