Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability
Plan PatchCVSS 8.6cisco-sa-iosxe-bing-MGHrFAkdAug 5, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software allows an unauthenticated remote attacker to cause a denial of service. An attacker can send a malformed BEEP SOAP request to an affected device, causing improper parsing that triggers an unexpected reload. This results in loss of network connectivity and service disruption. Cisco has released software updates to address this issue. No workarounds are available.
What this means
What could happen
An unauthenticated attacker can send a crafted BEEP SOAP request over the network to cause a router or switch to crash and reload, resulting in loss of network connectivity and service downtime.
Who's at risk
Network operators managing Cisco IOS XE routers and switches used in core infrastructure, branch offices, and service provider networks. This affects any Cisco device running affected IOS XE versions where BEEP is enabled, which is common on ASR, CSR, ISR, and Catalyst platforms used in municipal and utility networks for routing and access control.
How it could be exploited
An attacker on the network sends a malformed Blocks Extensible Exchange Protocol (BEEP) SOAP request to the affected Cisco device. The device fails to properly parse this request, triggering an unexpected reload. No authentication is required; the attacker only needs network access to the device's IP address.
Prerequisites
- Network access to the Cisco IOS XE device (any protocol capable of reaching the device)
- BEEP feature must be enabled on the device (default on many Cisco platforms)
- No credentials required
remotely exploitableno authentication requiredlow complexityhigh availability impactaffects network infrastructure devices
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
Cisco IOS XE Software Blocks Extensible Exchange Protocol16.10.1 through 26.2.1eaFix available
Remediation & Mitigation
0/3
Do now
0/2WORKAROUNDIf immediate patching is not feasible, disable the BEEP (Blocks Extensible Exchange Protocol) feature if not required for your network operations.
HARDENINGRestrict network access to the Cisco device by limiting source IP addresses allowed to communicate with BEEP management ports using firewall rules or access control lists (ACLs).
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Cisco IOS XE Software to version 16.10.1 or later, or to a patched version above 26.2.1ea.
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ca19312f-abc8-426f-9f4b-e5f5e228757cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.