PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-20084 Cisco CVE debrief

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This occurs due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device, potentially leading to BOOTP VLAN leakage and high CPU utilization, making the device unreachable and unable to forward traffic.

Vendor
Cisco
Product
Cisco IOS XE Software
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-25
Original CVE updated
2026-09-28
Advisory published
2026-03-25
Advisory updated
2026-09-28

Who should care

Network administrators and security teams responsible for managing Cisco IOS XE Software devices, particularly those using DHCP snooping features, should assess exposure and prioritize patching or applying workarounds.

Why it matters

CVE-2026-20084 is a high-severity vulnerability in Cisco IOS XE Software's DHCP snooping feature that could allow an unauthenticated remote attacker to cause a DoS condition. Network administrators and security teams should assess exposure, especially for devices using DHCP snooping, and prioritize patching or applying workarounds. The vulnerability's impact is supported by official Cisco and NVD sources, but specific version details and full remediation guidance require verification from these sources.

  • Denial of service (DoS) condition due to high CPU utilization.
  • BOOTP VLAN leakage potentially leading to network topology issues.
  • Device may become unreachable through console or remote management.
  • Traffic forwarding may be disrupted.

Technical summary

The vulnerability is caused by improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches running Cisco IOS XE Software. An unauthenticated, remote attacker can exploit this by sending BOOTP request packets to an affected device, potentially leading to BOOTP VLAN leakage and high CPU utilization, making the device unreachable and unable to forward traffic, resulting in a DoS condition.

Defensive priority

High

Recommended defensive actions

  • Network administrators should review and apply the available workarounds to address this vulnerability.
  • Administrators should prioritize patching affected systems, especially those exposed to the internet or untrusted networks.
  • Implementing ingress filtering to block BOOTP packets from untrusted sources can help mitigate the vulnerability.
  • Monitoring system logs for suspicious BOOTP activity can aid in early detection of potential attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-20084 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-20084

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-20084 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20084

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootp-WuBhNBxA

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.