Cisco IOS XE

Cisco · current 17.18

The current version of Cisco IOS XE is 17.18 (as of 26/07/2026). patchletter checks the official source daily and emails you every new release.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.

  • CVE-2023-20198Cisco IOS XE Web UI Privilege Escalation Vulnerability

    10.0 critical · over the network, without login · CISA deadline was 20 Oct 23

  • CVE-2018-0171Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2017-12240Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 24 Mar 22

  • CVE-2018-0151Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2017-3881Cisco IOS and IOS XE Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 15 Apr 22

  • CVE-2017-6736Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22

  • CVE-2017-6737Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22

  • CVE-2017-6738Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22

  • CVE-2017-6739Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22

  • CVE-2017-6740Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22

  • CVE-2017-6743Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22

  • CVE-2018-0167Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

    8.8 high · from the local network, without login · CISA deadline was 17 Mar 22

  • CVE-2017-6742Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 10 May 23

  • CVE-2018-0172Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

    8.6 high · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2018-0173Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

    8.6 high · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2018-0174Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

    8.6 high · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2018-0158Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

    8.6 high · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2018-0175Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

    8.0 high · from the local network, without login, needs user action · CISA deadline was 17 Mar 22

  • CVE-2025-20352Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

    7.7 high · over the network, with a basic account · CISA deadline was 20 Oct 25

  • CVE-2017-12237Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

    7.5 high · over the network, without login · CISA deadline was 24 Mar 22

  • CVE-2017-6627Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

    7.5 high · over the network, without login · CISA deadline was 24 Mar 22

  • CVE-2016-6415Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

    7.5 high · over the network, without login · CISA deadline was 9 Jun 23

  • CVE-2018-0156Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

    7.5 high · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2018-0159Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

    7.5 high · over the network, without login · CISA deadline was 17 Mar 22

  • CVE-2023-20273Cisco IOS XE Web UI Command Injection Vulnerability

    7.2 high · over the network, with admin rights only · CISA deadline was 27 Oct 23

  • CVE-2023-20109Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

    6.6 medium · over the network, with admin rights only · CISA deadline was 31 Oct 23

  • CVE-2017-6663Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

    6.5 medium · from the local network, without login · CISA deadline was 24 Mar 22

  • CVE-2017-12319Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

    5.9 medium · over the network, without login · CISA deadline was 24 Mar 22

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Cisco IOS XE at a glance

Cisco IOS XE is the operating system on many Cisco routers, switches and wireless controllers. Cisco ships IOS XE releases plus security advisories; as core network infrastructure that has seen actively exploited vulnerabilities (notably in the web UI), prompt patching is essential.

For admins the essentials: never expose the web management interface to untrusted networks, apply advisories on a priority basis, and pick the right IOS XE train per platform. Take a config backup before upgrading and use a maintenance window; verify routing/switching and critical services afterwards. Track the software version and its support lifecycle per device — hardware past support gets no fixes. Subscribe to Cisco's security advisories; patchletter surfaces new IOS XE releases automatically.

Support cycles (endoflife.date)

CycleLatest versionStatus
17.18LTSEOL 8 Aug 29
17.17End of Life
17.16End of Life
17.15LTSEOL 9 Aug 28
17.14End of Life
17.13End of Life
17.12LTSEOL 28 Jul 27
17.11End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
17.18LTS26/07/2026Release notes →

Frequently asked questions

What is the latest version of Cisco IOS XE?
Cisco IOS XE 17.18, released 26/07/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Cisco IOS XE release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Cisco IOS XE updates?
Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.

Never miss a Cisco IOS XE update

We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.

Watch Cisco IOS XE

Embed this badge

Shows the current Cisco IOS XE version and updates itself. Free to use, no account needed.

Cisco IOS XE badge
[![Cisco IOS XE](https://patchletter.com/badge/cisco-ios-xe.svg)](https://patchletter.com/en/software/cisco-ios-xe)
https://patchletter.com/badge/cisco-ios-xe.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Network, Switches & Wi-Fi