CVE-2026-20115: Cisco IOS XE Software
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path attack between the affected device and the Cisco Meraki Dashboard. A successful exploit could allow the attacker to view sensitive device configuration information.
Affected products
- Cisco Cisco IOS XE Software: version 17.14.1 only; version 17.14.1a only; version 17.15.1 only; version 17.15.1w only; version 17.15.1a only; version 17.15.2 only; …
Published 2026-03-25. Last modified 2026-06-17.