logo

Cisco Alert: Public Vulnerabilities in IOS XE Risk Service Denial and Privilege Escalation

ID: 4b4baca0-84d2-522a-a9dc-f33c4dfdadaa

STIX ID: report--4b4baca0-84d2-522a-a9dc-f33c4dfdadaa

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco published advisories for two Cisco IOS XE vulnerabilities: CVE-2026-20110 allows an authenticated, low-privileged CLI user to trigger maintenance mode (shutting down interfaces and causing DoS) due to an incorrect privilege assignment; CVE-2026-20114 enables an authenticated Lobby Ambassador user to create a new user with elevated management API access because API parameters are insufficiently validated. Cisco provides a manual workaround for the CLI DoS (reassigning the command to privilege level 15) and has released software updates for both flaws; there are no known active exploits according to Cisco.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.