PDF(51.4 KB) View with Adobe Reader on a variety of devices
ePub(87.8 KB) View in various apps on iPhone, iPad, Android, Sony Reader, or Windows Phone
Mobi (Kindle)(78.0 KB) View on Kindle device or Kindle app on multiple devices
Updated:August 17, 2026
Document ID:226259
Bias-Free Language
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Contents
Introduction
This document describes the wireless software bugs reported with the hardened security releases published for the Cisco IOSĀ® XE advisory Aug 2026.
Background
This document provides upgrade guidance to address Security Advisory, FN74383 and the critical issues.
On Aug 5th, 2026 Cisco released Cisco IOS XE Security Hardening Advisory that impacts multiple platforms, including but not limited to, 9800 series Wireless LAN Controllers. As documented, this advisory addresses multiple internally discovered vulnerabilities resulting from a comprehensive internal security review by Cisco IOS XE Engineering.
Embedded Wireless 9800 on Catalyst Switch (9800-SW) - only supports SDA deployment
COS based Catalyst 11ax 91xx Series Access Points (9105/9115/9117/9120/9130/9136/9164/9166)
Cisco Wireless 917x Series Access Points (CW9171/CW9172/CW9174/CW9176/CW9178/CW9179)
Cisco IOS XE Software Release
First Fixed Release
17.9
17.9.10
17.12
17.12.8
17.15
17.15.6
17.18
17.18.4, 17.18.4a*
26.1
26.1.2
Table 1. Software Releases included in review and corresponding hardened releases
*Note: 17.18.4a supports all the standalone WLCs. For the embedded Wireless Lan Controller on switches in SDA deployments, use the 17.18.4 wireless package that works with the 17.18.4 switch release. There is no 17.18.4a version for switch or wireless package.
Critical Bugs
In the security hardened releases mentioned in Table 1, some critical issues have been identified that can affect your use of these releases:
Symptom: Anchored wireless clients stuck at IP_Learn when C9800-L, CW9800-L, C9800-CL are configured as foreign WLC.
Affected Platforms: C9800-L, CW9800-L, C9800-CL (Only in Guest-Anchor scenario where the affected platforms act as foreign WLC).
Affected Software version: Cisco IOS XE 26.1.2, Cisco IOS XE 17.18.4a, Cisco IOS XE 17.15.6.
Workaround: Enable Mobility Data-link encryption at the tunnel between the foreign and the anchor:
wireless mobility group member mac-address <peer_mac> ip <peer_ip> public-ip <peer_ip> group <peer_group> data-link-encryption
To address both the advisory and critical issues reported on security hardened releases, Cisco recommends:
Wireless customers running Cisco IOS XE version 17.12, 17.15, 17.18 proceed to Steps 2, 3 and 4. Wireless customers running Cisco IOS XE version 17.9, 26.1, wait for APSP patch to get posted to cisco.com BEFORE upgrading. Refer to Table 2 for patch release dates.
Prior to the upgrade, run the upgrade checks and recovery steps documented here to mitigate the impact due to FN74383.
Upgrade the security hardened Cisco IOS XE version and the APSP patch in the same maintenance window to avoid wireless service being impacted.
If impacted by Cisco bug ID CSCwv98483, apply the workaround until SMU becomes available. Once SMU is posted, customers are expected to apply SMU patch.
Downtime Considerations for planning Maintenance Window for Cisco IOS XE upgrade + Patches
Cisco IOS XE upgrade on 9800 WLCs configured in non-redundant or high availability (HA) redundant configurations can leverage various mechanisms like:
To plan your maintenance window for Cisco IOS XE upgrade + patching with each upgrade mechanisms, take into account the downtime and impact documented in this section.
In-Service Software Upgrade (ISSU)
Applicable only to 9800 WLC pair running in HA Stateful Switchover (HA SSO) configuration and only supported between long-lived release trains and their maintenance releases. (Not supported on escalation releases and short-lived release trains with no maintenance releases).
ISSU provides seamless upgrade experience by supporting 9800 pair in HA SSO while running different software versions and leveraging rolling AP upgrade. On an operational 9800 HA pair, standby WLC is upgraded, and post SSO, new standby WLC is upgraded. For details of ISSU process and corresponding CLIs and GUI snapshots, refer to Upgrade 9800 HA SSO using ISSU.
Run the upgrade checks and recovery on APs prior to initiating ISSU.
With ISSU, upgrade duration is not easily predictable. Depending on the size of deployment and network speeds, upgrade can take multiple "hours" to complete.
Further, ISSU leverages rolling AP upgrade where APs are rebooted in staggered fashion to minimize downtime. However, in this case, it means clients connected to APs running hardened release continue to experience connectivity and roaming issues documented in Cisco bug IDs CSCwv93265 and CSCwv98483 until WLC is patched post ISSU upgrade.
SMU for Cisco bug ID CSCwv98483 is a cold patch that requires WLC reload.
APSP for Cisco bug ID CSCwv93265 can be applied using Rolling AP upgrade or in one-shot. If using Rolling AP upgrade, depending on the size of the deployment, this can take several "hours" for all APs to be upgraded and definitely avoid known critical bugs.
Total duration where service can be impacted (either WLC or APs are down OR client connectivity/roaming is impacted) = Time to complete ISSU + Time for WLC reload due to SMU cold patch + Time for AP rolling upgrade for APSP.
N+1 Rolling AP Upgrade
This procedure relies on an spare 9800 WLC called as N+1 WLC with upgraded software version to host APs while "production" 9800 pair or 9800 standalone undergoes upgrade. The recommendation is for this N+1 9800 WLC to have no APs registered to it BEFORE the N+1 rolling upgrade is initiated.
Run the upgrade checks and recovery on APs while they are registered to the primary WLC.
In this process, for APs to seamlessly roll over from primary WLC to the N+1 WLC, the software version running on N+1 WLC and pre-downloaded to APs needs to match exactly.
Pre-download to APs is facilitated by downloading, but NOT Activating Cisco IOS XE hardened release on primary WLC. Without image activation, software patches cannot be applied or pre-downloaded to APs. Which in turn, means N+1 WLC cannot be patched as well.
Even in this process, like ISSU, APs rolled over to N+1 WLC continue to be at risk for client connectivity and roaming issues documented in Cisco bug IDs CSCwv93265 and CSCwv98483 until N+1 WLC is patched, after Rolling AP upgrade finishes.
SMU for Cisco bug ID CSCwv98483 is a cold patch that requires WLC reload.
APSP for Cisco bug ID CSCwv93265 can be applied using Rolling AP upgrade or in one-shot. If using Rolling AP upgrade, depending on the size of the deployment, this can take several "hours" for all APs to be upgraded and definitely avoid known critical bugs.
Total duration where service can be impacted (either WLC or APs are down OR client connectivity/roaming is impacted) = Time taken for all APs to rollover to N+1 WLC + Time for WLC reload due to SMU cold patch + Time for AP rolling upgrade for APSP.
For your maintenance window, also take into account time taken for N+1 WLC to be upgraded to Cisco IOS XE hardened releases and for APs to pre-download Cisco IOS XE hardened release from primary WLC, though neither of this has any service impact.
N+1 Regular AP Upgrade - RECOMMENDED
This procedure relies on an spare 9800 WLC callas as N+1 WLC with upgraded software version to host APs while "production" 9800 pair or 9800 standalone undergoes upgrade.
The recommendation is for this spare 9800 WLC to have no APs registered to it BEFORE the N+1 rolling upgrade is initiated.
The spare N+1 WLC can be upgraded to hardened Cisco IOS XE activated and committed and patched with APSP and SMU, in one-shot. With no APs registered, this is non-service impact but you must account for the time taken for multiple WLC reload when scheduling your maintenance window.
On the primary WLC GUI where APs are registered, navigate to Configuration > Tags and Profiles: AP Priming > Primary Base.
Define N+1 WLC and Wireless Management Interface (WMI) IP Address as primary.
Define current primary WLC name and WMI IP under Secondary.
Use regex filters to bulk migrate APs from primary WLC to N+1 WLC.
Once registered to N+1 WLC, APs are already running security hardened release along with patches to fix critical bugs.
Total duration where service can be impacted (either WLC or APs are down OR client connectivity/roaming is impacted) = Time taken for APs to migrate from primary WLC to N+1 WLC which is dictated by network speed between AP and WLCs.
One-Shot Upgrade - RECOMMENDED, if no N+1 WLC present
In this procedure, the primary WLC is upgraded (along with activation and commitment) to security hardened Cisco IOS XE release in one step.
As part of image Activation, primary WLC gets reloaded and all APs re-register with upgrade primary WLC and receive the security hardened Cisco IOS XE release.
Until APSP is applied, APs are at risk for client connectivity and roaming issues documented in Cisco bug IDs CSCwv93265 and CSCwv98483.
Total duration where service can be impacted (either WLC or APs are down OR client connectivity/roaming is impacted) = Time taken for primary WLC to reload + Time taken for all APs to download hardened Cisco IOS XE release from primary WLC over CAPWAP and register back to primary WLC. (Double this time if SMU patch is being applied) + Time taken for all APs to download APSP patch from primary WLC and register back to primary WLC.
Frequently Asked Questions
Q1. Are APs impacted by this Security Advisory?
COS based Access Points were included in the security review and the corresponding fixes are incorporated into the hardened Cisco IOS XE releases.
Q2. What is the risk for AireOS WLCs?
AireOS WLCs was not included in the security review as it has reached Last Day of Support (LDoS).
Q3: Is there a release that includes all the fixes so that a single upgrade action can be taken?
Cisco is considering this and may post further information if it becomes available.
An escalation special release is available that includes the APSP upon requesting TAC. That escalation special release does not allow further SMUs or APSPs to be installed on it and it only contains the fix from APSP1.
Revision History
Revision
Publish Date
Comments
3.0
17-Aug-2026
Added a note about Cisco Essentials license customers as well as 26.1 APSP link