CVE-2026-20113Patch

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-26: 1Mentions · 2026-03-30: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-30: 103-2603-30
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-261
Patch1
2026-03-301
Disclosure1
Full discourse2 posts
  • Gray Hats@the_yellow_fall
    Patch

    Cisco alerts of public flaws in IOx app hosting. Unauthenticated actors can manipulate logs (CVE-2026-20113), plus a stored XSS risk (CVE-2026-20112). Patch now! #Cisco #IOSXE #InfoSec #CyberSecurity #Networking #XSS #LogInjection #PatchNow #CiscoIOx https://securityonline.info/cisco-iox-ios-xe-public-vulnerabilities-xss-crlf-injection/ https://t.co/pAuDcwL4Lv

    Post summary

    Cisco alerts that two public flaws (CVE-2026-20113 and CVE-2026-20112) affect IOx app hosting and urges users to apply available patches immediately.

    060123746
    10.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20113 A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attack… https://www.cve.org/CVERecord?id=CVE-2026-20113

    Post summary

    The statement provides a basic disclosure of CVE‑2026‑20113, noting it targets the Cisco IOx application hosting environment management interface and could allow unauthenticated remote attacks, without additional details on exploitation or mitigation.

    00010158
    56.8K followersView on X

Explore more