This document describes the wireless software bugs reported with the hardened security releases published for the Cisco IOSĀ® XE advisory Aug 2026.
This document provides upgrade guidance to address Security Advisory, FN74383 and the critical issues.
On Aug 5th, 2026 Cisco released Cisco IOS XE Security Hardening Advisory that impacts multiple platforms, including but not limited to, 9800 series Wireless LAN Controllers. As documented, this advisory addresses multiple internally discovered vulnerabilities resulting from a comprehensive internal security review by Cisco IOS XE Engineering.
Wireless Platforms included in the review
Catalyst Wireless 9800 (C9800-L, C9800-CL, C9800-40, C9800-80)
Cisco Wireless 9800 WLC (CW9800L, CW9800M, CW9800H1/H2
Embedded Wireless 9800 on Catalyst Switch (9800-SW) - only supports SDA deployment
COS based Catalyst 11ax 91xx Series Access Points (9105/9115/9117/9120/9130/9136/9164/9166)
Cisco Wireless 917x Series Access Points (CW9171/CW9172/CW9174/CW9176/CW9178/CW9179)
| Cisco IOS XE Software Release | First Fixed Release |
| 17.9 | 17.9.10 |
| 17.12 | 17.12.8 |
| 17.15 | 17.15.6 |
| 17.18 | 17.18.4, 17.18.4a* |
| 26.1 | 26.1.2 |
Table 1. Software Releases included in review and corresponding hardened releases
In the security hardened releases mentioned in Table 1, some critical issues have been identified that can affect your use of these releases:
Cisco bug ID CSCwv93265:
Symptom: Client Connectivity or Roaming Failures when OpenRoaming, WPA3, 11k, 11v, 11r features are in use.
Affected Platforms: All Cisco 9800 Wireless Controller and Wireless Package for Cat9K.
Affected Software version: Cisco IOS XE 26.1.2, Cisco IOS XE 17.18.4a, Cisco IOS XE 17.18.4, Cisco IOS XE 17.15.6, Cisco IOS XE 17.12.8, Cisco IOS XE 17.9.10.
A corrective APSP is available for all releases. Cisco recommends deploying APSP on all deployments running the hardening release.
Note: This APSP is exceptionally available to Essentials licensing customers as well. Contact TAC to have it published in case you cannot download it.
Fixed Release:
| C9800-L | CW9800-L | C9800-40 | C9800-80 | C9800-CL | CW9800-M | CW9800-H1 | CW9800-H2 | cat9k Switches | C9350 | EWC-on-9100s | |
| 17.15.6 | APSP-Link | NA | APSP-Link | APSP-Link | APSP-Link | APSP-Link | APSP-Link | APSP-Link | APSP-Link | NA | Contact TAC to get Engineering Special build |
| 17.18.4a | APSP-Link | APSP-Link | APSP-Link | APSP-Link | APSP-Link | APSP-Link | APSP-Link | APSP-Link | NA | NA | NA |
| 17.18.4 | NA | NA | NA | NA | NA | NA | NA | NA | APSP-Link | NA | NA |
| 17.12.8 | APSP-Link | NA | APSP-Link | APSP-Link | NA | NA | NA | APSP-Link | NA | Move to 17.15 train | |
| 26.1.2 | APSP link | APSP link | APSP link | APSP link | APSP link | APSP link | APSP link | APSP link | APSP link | APSP link | NA |
| 17.9.10 | APSP-Link | NA | APSP-Link | APSP-Link | NA | NA | NA | APSP-Link | NA | Move to 17.15 train |
Table 2. APSP links for different 9800 WLC platforms
Cisco bug ID CSCwv98483
Symptom: Anchored wireless clients stuck at IP_Learn when C9800-L, CW9800-L, C9800-CL are configured as foreign WLC.
Affected Platforms: C9800-L, CW9800-L, C9800-CL (Only in Guest-Anchor scenario where the affected platforms act as foreign WLC).
Affected Software version: Cisco IOS XE 26.1.2, Cisco IOS XE 17.18.4a, Cisco IOS XE 17.15.6.
Workaround: Enable Mobility Data-link encryption at the tunnel between the foreign and the anchor:
wireless mobility group member mac-address <peer_mac> ip <peer_ip> public-ip <peer_ip> group <peer_group> data-link-encryption
Fixed Release:
| Product |
C9800L |
CW9800L |
C9800-CL |
| 17.15.6 |
NA |
||
| 17.18.4a |
|||
| 26.1.2 |
To address both the advisory and critical issues reported on security hardened releases, Cisco recommends:
Cisco IOS XE upgrade on 9800 WLCs configured in non-redundant or high availability (HA) redundant configurations can leverage various mechanisms like:
For details, refer to the 9800 WLC Upgrade Quick Start Guide.
In addition, the critical issues require patching with Software Maintenance Update (SMU) and Access Point Service Pack (APSP).
For details on various patching options supported by 9800 WLC, refer to Patching and Rolling AP Upgrade Guide for 9800 WLC.
To plan your maintenance window for Cisco IOS XE upgrade + patching with each upgrade mechanisms, take into account the downtime and impact documented in this section.
Total duration where service can be impacted (either WLC or APs are down OR client connectivity/roaming is impacted) = Time taken for APs to migrate from primary WLC to N+1 WLC which is dictated by network speed between AP and WLCs.
Total duration where service can be impacted (either WLC or APs are down OR client connectivity/roaming is impacted) = Time taken for primary WLC to reload + Time taken for all APs to download hardened Cisco IOS XE release from primary WLC over CAPWAP and register back to primary WLC. (Double this time if SMU patch is being applied) + Time taken for all APs to download APSP patch from primary WLC and register back to primary WLC.
Are APs impacted by this Security Advisory?
COS based Access Points were included in the security review and the corresponding fixes are incorporated into the hardened Cisco IOS XE releases.
What is the risk for AireOS WLCs?
AireOS WLCs was not included in the security review as it has reached Last Day of Support (LDoS).
Is there a release that includes all the fixes so that a single upgrade action can be taken?
Cisco is considering this and may post further information if it becomes available. An escalation special release is available that includes the APSP upon requesting TAC. That escalation special release does not allow further SMUs or APSPs to be installed on it and it only contains the fix from APSP1.
| Revision | Publish Date | Comments |
|---|---|---|
3.0 |
17-Aug-2026
|
Added a note about Cisco Essentials license customers as well as 26.1 APSP link |
2.0 |
14-Aug-2026
|
Added EWC-on-AP |
1.0 |
13-Aug-2026
|
Initial Release |