PatchSiren cyber security CVE debrief
CVE-2026-20084 Cisco CVE debrief
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This occurs due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device, potentially leading to BOOTP VLAN leakage and high CPU utilization, making the device unreachable and unable to forward traffic.
- Vendor
- Cisco
- Product
- Cisco IOS XE Software
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-25
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-03-25
- Advisory updated
- 2026-09-28
Who should care
Network administrators and security teams responsible for managing Cisco IOS XE Software devices, particularly those using DHCP snooping features, should assess exposure and prioritize patching or applying workarounds.
Why it matters
CVE-2026-20084 is a high-severity vulnerability in Cisco IOS XE Software's DHCP snooping feature that could allow an unauthenticated remote attacker to cause a DoS condition. Network administrators and security teams should assess exposure, especially for devices using DHCP snooping, and prioritize patching or applying workarounds. The vulnerability's impact is supported by official Cisco and NVD sources, but specific version details and full remediation guidance require verification from these sources.
- Denial of service (DoS) condition due to high CPU utilization.
- BOOTP VLAN leakage potentially leading to network topology issues.
- Device may become unreachable through console or remote management.
- Traffic forwarding may be disrupted.
Technical summary
The vulnerability is caused by improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches running Cisco IOS XE Software. An unauthenticated, remote attacker can exploit this by sending BOOTP request packets to an affected device, potentially leading to BOOTP VLAN leakage and high CPU utilization, making the device unreachable and unable to forward traffic, resulting in a DoS condition.
Defensive priority
High
Recommended defensive actions
- Network administrators should review and apply the available workarounds to address this vulnerability.
- Administrators should prioritize patching affected systems, especially those exposed to the internet or untrusted networks.
- Implementing ingress filtering to block BOOTP packets from untrusted sources can help mitigate the vulnerability.
- Monitoring system logs for suspicious BOOTP activity can aid in early detection of potential attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-20084 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-20084
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-20084 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20084
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootp-WuBhNBxA
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.