CVE-2026-20084

HIGH

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of ...

Affects 0 products across 2 vendors.

BCS5.87
CVSS 3.18.6
EPSS0.4%
Percentile28th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, no confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-400: Uncontrolled Resource Consumption (DoS)

Software does not properly limit resource usage, allowing an attacker to exhaust CPU, memory, disk, or bandwidth.

Related Attack Patterns (CAPEC)
CAPEC-147 XML Ping of the Death
via CWE-400
CAPEC-492 Regular Expression Exponential Blowup
via CWE-400
CAPEC-227 Sustained Client Engagement
via CWE-400

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition.

BSID: BS-2026-GLOBAL-063128-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20084?
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition.
What is the CVSS score for CVE-2026-20084?
CVE-2026-20084 has CVSS 8.6 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H. EPSS: 0.4%.
Is CVE-2026-20084 actively exploited?
No confirmed active exploitation of CVE-2026-20084 as of 2026-05-30.
How do I remediate CVE-2026-20084?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootp-WuBhNBxA PSIRT: [email protected]
What systems are affected by CVE-2026-20084?
CVE-2026-20084 affects: Catalyst, Cisco.
Vulnerability Details
CVE IDCVE-2026-20084
BSIDBS-2026-GLOBAL-063128-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Published2026-03-25
Last Modified2026-03-26
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device. A successful exploit could allow an attacker to forward BOOTP packets from one VLAN to another, resulting in BOOTP VLAN leakage and potentially leading to high CPU utilization. This makes the device unreachable (either through console or remote management) and unable to forward traffic, resulting in a DoS condition. Note: This vulnerability can be exploited with either unicast or broadcast BOOTP packets. There are workarounds that address this vulnerability.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP requests.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Catalyst —
Cisco —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 122 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash8cf41364422f6a8af1a758865fb4e34d8e2a9f4f48ec37ff7b93d105cd765703080c262fed3c231f76864764f5bf32b07a590ec3ffedc7ee9d88d573319ddcb7
Related CVEs affecting Catalyst
CVE-2026-26009 9.9 Catalyst is a platform built for enterprise game server hosts, game communiti... CVE-2025-20341 8.8 A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an aut... CVE-2026-20086 8.6 A vulnerability in the processing of Control and Provisioning of Wireless Acc... CVE-2026-20224 8.6 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-W... CVE-2025-40920 8.6 Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Per...
View all Catalyst CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →