Changeflow GovPing Data Privacy & Cybersecurity Multiple Cisco IOS and IOS XE Vulnerabilities I...
Priority review Notice Added Final

Multiple Cisco IOS and IOS XE Vulnerabilities Identified

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 26th, 2026
Detected March 26th, 2026
Email

Summary

CERT-FR has issued an advisory regarding multiple vulnerabilities discovered in Cisco IOS and IOS XE. These vulnerabilities could allow a remote attacker to cause a denial-of-service condition or bypass security policies. Cisco has released security bulletins with details and patches.

What changed

CERT-FR, the French national cybersecurity agency, has published an advisory (CERTFR-2026-AVI-0361) detailing multiple vulnerabilities affecting Cisco IOS and IOS XE operating systems. The identified issues, referenced by several Cisco security bulletins and CVEs, can enable remote attackers to achieve denial-of-service conditions and bypass security policies. The advisory directs users to Cisco's security bulletins for specific version information and available patches.

Organizations utilizing Cisco IOS or IOS XE are strongly advised to review the referenced Cisco security bulletins immediately. The primary action required is to apply the vendor-provided patches or implement recommended workarounds to mitigate the identified risks of service disruption and security policy circumvention. Failure to address these vulnerabilities could lead to significant network outages and security breaches.

What to do next

  1. Review Cisco security bulletins for affected IOS and IOS XE versions.
  2. Apply vendor-provided patches or implement recommended workarounds.
  3. Monitor network for signs of exploitation.

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 26 mars 2026 N° CERTFR-2026-AVI-0361 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Multiples vulnérabilités dans Cisco IOS et IOS XE

Gestion du document

| Référence | CERTFR-2026-AVI-0361 |
| Titre | Multiples vulnérabilités dans Cisco IOS et IOS XE |
| Date de la première version | 26 mars 2026 |
| Date de la dernière version | 26 mars 2026 |
| Source(s) | Bulletin de sécurité Cisco cisco-sa-asa-ftd-ios-dos-kPEpQGGK du 25 mars 2026
Bulletin de sécurité Cisco cisco-sa-bootp-WuBhNBxA du 25 mars 2026
Bulletin de sécurité Cisco cisco-sa-ios-http-dos-sbv8XRpL du 25 mars 2026
Bulletin de sécurité Cisco cisco-sa-iosxe-tls-dos-TVgLDEZL du 25 mars 2026
Bulletin de sécurité Cisco cisco-sa-wlc-dos-hnX5KGOm du 25 mars 2026
Bulletin de sécurité Cisco cisco-sa-xe-secureboot-bypass-B6uYxYSZ du 25 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risques

  • Contournement de la politique de sécurité
  • Déni de service à distance

Systèmes affectés

  • IOS XE, se référer au bulletin de sécurité de l'éditeur pour les versions vulnérables (cf. section Documentation)
  • IOS, se référer au bulletin de sécurité de l'éditeur pour les versions vulnérables (cf. section Documentation)

Résumé

De multiples vulnérabilités ont été découvertes dans Cisco IOS et IOS XE. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 26 mars 2026 Version initiale

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 26th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
CERTFR-2026-AVI-0361

Who this affects

Applies to
Technology companies
Industry sector
5170 Telecommunications 3341 Computer & Electronics Manufacturing
Activity scope
Network Security Vulnerability Management
Geographic scope
France FR

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Network Security Vulnerability Management

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.