CVE-2026-20171General

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If the update propagates to an affected device, it could cause the device to drop the BGP session and flap with the BGP peer that is forwarding this update, resulting in a DoS condition.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-670

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-20); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-20: 1Mentions · 2026-05-22: 1Mentions · 2026-05-23: 1Mentions · 2026-07-23: 1Patch / Workaround · 2026-07-23: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-23: 105-2005-2205-2307-23
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-201
General1
2026-05-221
Disclosure1
2026-05-231
General1
2026-07-231
Disclosure1
Full discourse4 posts
  • Israel@f1tym1
    General

    CVE-2026-20171 | Cisco NX-OS Software up to 10.6(1s) BGP Enforce-First-As Feature control flow (cisco-sa-bgp-iefab-3hb2pwtx) https://ift.tt/sMGRLDg A vulnerability has been found in Cisco NX-OS Software and classified as problematic. The impacted element is an unknown function…

    Post summary

    The post announces CVE-2026-20171 affecting Cisco NX-OS, provides minimal technical context, and offers no evidence of exploitation or remediation.

    0100093
    974 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-20171](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ci... https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bgp-iefab-3hb2pwtx #PatchManagement #Vulnerability #CVE

    Post summary

    The tweet informs users of the CVE-2026-20171 vulnerability via a Cisco advisory link, indicating patch availability but lacking detailed technical or exploit information.

    0000039
    13 followersView on X
  • Israel@f1tym1
    General

    CVE-2026-20171 | Cisco NX-OS Software up to 10.6(1s) BGP Enforce-First-As Feature control flow (cisco-sa-bgp-iefab-3hb2pwtx / WID-SEC-2026-1622) https://ift.tt/W0cXPwd A vulnerability has been found in Cisco NX-OS Software and classified as problematic. The impacted element is…

    Post summary

    The text announces CVE-2026-20171, a BGP control‑flow flaw in Cisco NX-OS, but provides no PoC, exploit, or patch details.

    00000108
    980 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-20171 | Cisco NX-OS Software up to 10.6(1s) BGP Enforce-First-As Feature control flow (cisco-sa-bgp-iefab-3hb2pwtx / WID-SEC-2026-1622) https://ift.tt/zhpxqSb A vulnerability has been found in Cisco NX-OS Software and classified as problematic. The impacted element is…

    Post summary

    Cisco issued an advisory for CVE‑2026‑20171, describing a BGP Enforce‑First‑As control flow vulnerability in NX‑OS up to 10.6(1s). The advisory provides technical details but does not mention a PoC, exploit code, patch, or active exploitation.

    0000056
    981 followersView on X

Explore more