CVE-2026-20118 is a denial-of-service vulnerability in Cisco IOS XR Software affecting NCS 5500 Series with NC57 line cards and NCS 5700 Routers. This flaw involves packet corruption during Egress Packet Network Interface (EPNI) Aligner interrupt handling under heavy transit traffic, which can cause the network processing unit (NPU) and ASIC to cease traffic processing. An unauthenticated, remote attacker can exploit this by sending a continuous flow of crafted packets, leading to persistent, heavy packet loss and a denial-of-service condition. While the technical attack complexity is high, Cisco has assigned a Security Impact Rating of High due to the critical network segment where these devices operate. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco IOS XR Software | 24.1.1, 24.1.2, 24.2.1, 24.2.11, 24.2.2, 24.2.20, 24.2.21, 24.3.1, 24.3.2, 24.3.20, 24.3.30, 24.4.1, 24.4.2, 24.4.30, 25.1.1, 25.1.2, 7.10.1, 7.10.2, 7.11.1, 7.11.2, 7.11.21, 7.9.1, 7.9.2CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco IOS XR Egress Packet Network Interface Aligner Interrupt Denial of Service Vulnerability
Mar 11, 2026Cisco IOS XR Egress Packet Network Interface Aligner Interrupt Denial of Service Vulnerability
Mar 11, 2026Cisco IOS XR Egress Packet Network Interface Aligner Interrupt Denial of Service Vulnerability
Mar 11, 2026Cisco IOS XR Egress Packet Network Interface Aligner Interrupt Denial of Service Vulnerability
Mar 11, 2026