Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Cisco Patches Eight IOS XR Vulnerabilities, Including Three Critical Flaws

Cisco has patched eight vulnerabilities affecting its IOS XR operating system, including three rated critical. The company said it found no evidence that any of the flaws had been exploited in the wild.

Cisco described the findings in two advisories published on September 2. One advisory covers seven vulnerabilities, including CVE-2026-20274 and CVE-2026-20279, both rated 9.8/10. The flaws affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration. Cisco said there are no available workarounds and that installing the provided patch is the only mitigation.

The third critical vulnerability, CVE-2026-20212, affects Cisco Nexus 9000 Series Switches that include a Silicon One ASIC. Successful exploitation could let attackers connect to an affected device and send crafted input that runs as code without root privileges. Cisco said exploitation could also crash the S1HAL process and cause the device to reload.

Cisco urged customers to apply the patches as soon as possible. For CVE-2026-20212, it described infrastructure access control lists, or iACLs, as possible workarounds. These can restrict management and control plane traffic or deny TCP packets sent to locally configured IP addresses on destination ports 43210 or 43211.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.