Cisco IOS XE
Cisco · current 17.18
The current version of Cisco IOS XE is 17.18 (as of 26/07/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
- CVE-2023-20198Cisco IOS XE Web UI Privilege Escalation Vulnerability
10.0 critical · over the network, without login · CISA deadline was 20 Oct 23
- CVE-2018-0171Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 3 May 22
- CVE-2017-12240Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 24 Mar 22
- CVE-2018-0151Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 17 Mar 22
- CVE-2017-3881Cisco IOS and IOS XE Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 15 Apr 22
- CVE-2017-6736Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22
- CVE-2017-6737Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22
- CVE-2017-6738Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22
- CVE-2017-6739Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22
- CVE-2017-6740Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22
- CVE-2017-6743Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 24 Mar 22
- CVE-2018-0167Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
8.8 high · from the local network, without login · CISA deadline was 17 Mar 22
- CVE-2017-6742Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 10 May 23
- CVE-2018-0172Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
8.6 high · over the network, without login · CISA deadline was 17 Mar 22
- CVE-2018-0173Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
8.6 high · over the network, without login · CISA deadline was 17 Mar 22
- CVE-2018-0174Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability
8.6 high · over the network, without login · CISA deadline was 17 Mar 22
- CVE-2018-0158Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
8.6 high · over the network, without login · CISA deadline was 17 Mar 22
- CVE-2018-0175Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
8.0 high · from the local network, without login, needs user action · CISA deadline was 17 Mar 22
- CVE-2025-20352Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
7.7 high · over the network, with a basic account · CISA deadline was 20 Oct 25
- CVE-2017-12237Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
7.5 high · over the network, without login · CISA deadline was 24 Mar 22
- CVE-2017-6627Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
7.5 high · over the network, without login · CISA deadline was 24 Mar 22
- CVE-2016-6415Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
7.5 high · over the network, without login · CISA deadline was 9 Jun 23
- CVE-2018-0156Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
7.5 high · over the network, without login · CISA deadline was 17 Mar 22
- CVE-2018-0159Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability
7.5 high · over the network, without login · CISA deadline was 17 Mar 22
- CVE-2023-20273Cisco IOS XE Web UI Command Injection Vulnerability
7.2 high · over the network, with admin rights only · CISA deadline was 27 Oct 23
- CVE-2023-20109Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
6.6 medium · over the network, with admin rights only · CISA deadline was 31 Oct 23
- CVE-2017-6663Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
6.5 medium · from the local network, without login · CISA deadline was 24 Mar 22
- CVE-2017-12319Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability
5.9 medium · over the network, without login · CISA deadline was 24 Mar 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- http/2 Implementierungen: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2023-2618 · 14 Aug
- Cisco IOS: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2026-2664 · 6 Aug
- Cisco IOS XE: Mehrere Schwachstellen
WID-SEC-W-2026-2674 · 6 Aug
Cisco IOS XE at a glance
Cisco IOS XE is the operating system on many Cisco routers, switches and wireless controllers. Cisco ships IOS XE releases plus security advisories; as core network infrastructure that has seen actively exploited vulnerabilities (notably in the web UI), prompt patching is essential.
For admins the essentials: never expose the web management interface to untrusted networks, apply advisories on a priority basis, and pick the right IOS XE train per platform. Take a config backup before upgrading and use a maintenance window; verify routing/switching and critical services afterwards. Track the software version and its support lifecycle per device — hardware past support gets no fixes. Subscribe to Cisco's security advisories; patchletter surfaces new IOS XE releases automatically.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 17.18LTS | – | EOL 8 Aug 29 |
| 17.17 | – | End of Life |
| 17.16 | – | End of Life |
| 17.15LTS | – | EOL 9 Aug 28 |
| 17.14 | – | End of Life |
| 17.13 | – | End of Life |
| 17.12LTS | – | EOL 28 Jul 27 |
| 17.11 | – | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 17.18 | LTS | 26/07/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Cisco IOS XE?
- Cisco IOS XE 17.18, released 26/07/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Cisco IOS XE release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Cisco IOS XE updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Cisco IOS XE update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch Cisco IOS XEEmbed this badge
Shows the current Cisco IOS XE version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/cisco-ios-xe)https://patchletter.com/badge/cisco-ios-xe.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).