AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-20124

HIGH · CVSS 7.7 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the SNMP subsystem of Cisco IOS XE Software allows an authenticated remote attacker to exploit improper error handling, potentially leading to a denial of service (DoS) by causing the affected device to unexpectedly reload. This issue impacts all versions of SNMP (1, 2c, and 3), and exploitation requires valid SNMP community strings or credentials. Organizations using Cisco devices with SNMP enabled should prioritize patching to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-20124
Severity
HIGH
CVSS
7.7
EPSS
0.34%
Cisco

Original NVD Description

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.