Description
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.
Published: 2026-08-05
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the handling of XMCP packets in Cisco IOS and IOS XE software. A malformed packet can trigger an application crash that causes the device to reload, resulting in a loss of service. The weakness is a failure to validate input (CWE‑606) and does not require authentication. The attack could lead to a total outage of the affected router or switch, impacting both local and remote network traffic.

Affected Systems

This vulnerability affects Cisco IOS and Cisco IOS XE software. Specific version information is not disclosed in the advisory, so all installations of these products that are not patched by Cisco are potentially exposed.

Risk and Exploitability

With a CVSS score of 8.6 the vulnerability is considered high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is remote; an unauthenticated attacker can send a crafted XMCP packet over the network to the target device. Likely exploitation requires only network access to the XMCP port and no credentials, making the threat practical for attackers who gain foothold in the same subnet or can reach the device externally.

Generated by OpenCVE AI on August 5, 2026 at 18:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Cisco update released for this vulnerability as detailed in the Cisco Security Advisory
  • If an immediate patch is not possible, disable the XMCP service or restrict it with ACLs to limit access to trusted hosts
  • Configure alerting and monitoring for unexpected reloads or restart events on the device

Generated by OpenCVE AI on August 5, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco ios
Cisco ios Xe Software
Vendors & Products Cisco
Cisco ios
Cisco ios Xe Software

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.
Title Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
Weaknesses CWE-606
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Cisco Ios Ios Xe Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-05T17:45:13.376Z

Reserved: 2025-10-08T11:59:15.408Z

Link: CVE-2026-20301

cve-icon Vulnrichment

Updated: 2026-08-05T17:39:00.784Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:50.187

Modified: 2026-08-06T15:44:56.043

Link: CVE-2026-20301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:15:07Z

Weaknesses
  • CWE-606

    Unchecked Input for Loop Condition