CVE-2026-20086 is a high-severity vulnerability (CVSS 8.6) impacting Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family. This flaw arises from improper handling of malformed Control and Provisioning of Wireless Access Points (CAPWAP) packets. An unauthenticated, remote attacker can exploit this to cause a Denial of Service (DoS) condition, leading to unexpected device reloads. While the attack complexity is low, there is currently no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco IOS XE Software | 17.14.1, 17.15.1, 17.15.2, 17.15.2b, 17.15.3, 17.15.4, 17.15.4d, 17.16.1, 17.17.1, 17.18.1CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family CAPWAP Denial of Service Vulnerability
Mar 25, 2026Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family CAPWAP Denial of Service Vulnerability
Mar 25, 2026Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family CAPWAP Denial of Service Vulnerability
Mar 25, 2026