Cisco Alert: Public Vulnerabilities in IOS XE Risk Service Denial and Privilege Escalation
ID: 4b4baca0-84d2-522a-a9dc-f33c4dfdadaa
STIX ID: report--4b4baca0-84d2-522a-a9dc-f33c4dfdadaa
Feed Name: securityonline.info
Cisco published advisories for two Cisco IOS XE vulnerabilities: CVE-2026-20110 allows an authenticated, low-privileged CLI user to trigger maintenance mode (shutting down interfaces and causing DoS) due to an incorrect privilege assignment; CVE-2026-20114 enables an authenticated Lobby Ambassador user to create a new user with elevated management API access because API parameters are insufficiently validated. Cisco provides a manual workaround for the CLI DoS (reassigning the command to privilege level 15) and has released software updates for both flaws; there are no known active exploits according to Cisco.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
