Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

MonitorCVSS 6.3cisco-sa-xe-webui-dos-PtAODAWWAug 5, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A vulnerability in the web-based management interface of Cisco IOS XE Software allows an authenticated remote attacker with low privileges to cause a denial of service. The vulnerability stems from insufficient error handling when processing malformed certificates during authentication. A successful exploit causes the affected device to reload, resulting in a denial of service condition. Affected versions include Cisco IOS XE Software 17.10.1 through 26.2.1ea.

What this means
What could happen
An authenticated attacker with low-privilege credentials could cause a network device running Cisco IOS XE to reload and go offline, disrupting network connectivity and any dependent operations until the device restarts.
Who's at risk
Network operators of Cisco IOS XE devices (routers, switches, wireless controllers) who rely on the web-based management interface for device administration. This affects any facility using Cisco network infrastructure, including utilities, manufacturing plants, and municipal networks that depend on these devices for operational connectivity.
How it could be exploited
An attacker with valid low-privilege credentials accesses the web-based management interface of the Cisco IOS XE device (typically reachable on port 443 for HTTPS) and presents a malformed certificate during authentication. The insufficient error handling causes the device to crash and reload, disrupting service.
Prerequisites
  • Valid low-privilege credentials (local or domain user account)
  • Network reachability to the web-based management interface port (typically HTTPS port 443)
  • Access to the management interface (may be restricted by firewall or network segmentation)
remotely exploitablelow complexityrequires valid credentialsaffects network availabilityno workaround available
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
Cisco IOS XE Software Web-Based Management Interface17.10.1 through 26.2.1eaFix available
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to the web-based management interface to trusted administrative IP addresses and networks using firewall rules or access control lists
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Cisco IOS XE Software to version 26.2.2 or later, or apply vendor-supplied patches for your specific version
HARDENINGDisable the web-based management interface if not required for operations and use SSH/CLI management instead
Long-term hardening
0/1
HARDENINGEnforce strong authentication credentials and disable low-privilege accounts that do not require web-based management access
API: /api/v1/advisories/d62b9ad9-9810-4189-a452-bc22f327ff43

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability | CVSS 6.3 - OTPulse