CVE-2026-88263: Xikestor SKS8300-12e2t2x

High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.

Affected products

  • Xikestor SKS8300-12e2t2x: before V1.04.B09 (fixed in V1.04.B09)
  • Xikestor SKS8300-8t: before V1.04.B09 (fixed in V1.04.B09)
  • Xikestor SKS8310-8x: before V1.04.B09 (fixed in V1.04.B09)

Published 2026-09-16. Last modified 2026-09-16.