Cisco IOS XE Software SNMP Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. There is a mitigation that addresses this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD Security Impact Rating: High CVE: CVE-2026-20124
CSIRTS triage
- What
- Improper error handling in the SNMP subsystem when parsing malformed SNMP requests causes device reload.
- Who is affected
- Devices with SNMP enabled (all versions 1, 2c, and 3) and accessible to authenticated attackers with SNMP credentials.
- Urgency
- High severity; denial of service through device reload; requires SNMP community string or SNMPv3 credentials.
- Action
- Apply Cisco IOS XE Software updates; mitigation available (specific details truncated in advisory).
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch IOS XE Software
Get an email when a new IOS XE Software advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-201240.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20124 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Cisco IOS XE: Multiple Vulnerabilitiescert-bund
- unknownCisco Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Cisco products (August 6, 2026)cert-fr-avis
- highCVE-2026-20124: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Sof…nvd
- criticalCisco Advance Notification for Publication of August 5, 2026, Security Advisoriescisco-psirt
Recent advisories for Cisco IOS XE
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)cert-fr-avis · 2026-08-25
- unknownNCSC-2026-0279 [1.00] [M/H] Vulnerabilities patched in Cisco IOS XE Softwarencsc-nl · 2026-08-07
- high[NEW] [high] Cisco IOS XE: Multiple Vulnerabilitiescert-bund · 2026-08-06
- mediumCVE-2026-20311: A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an …nvd · 2026-08-05
- mediumCVE-2026-20308: A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an …nvd · 2026-08-05
- highCVE-2026-20301: A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the Ex…nvd · 2026-08-05
More from Cisco Security Advisories
- criticalCisco IOS XR Software Security Hardening Release: September 20262026-09-04
- criticalCisco Advance Notification for Publication of September 2, 2026, Security Advisories2026-09-02
- highCisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of …2026-09-02
- mediumCisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities2026-09-02
- criticalCisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability2026-09-02