Cisco searched for IOS XR bugs and found so many it rolled them into an update release

← Back to the feed

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

The Register · 4 hours ago

Cisco has disclosed three critical-severity vulnerabilities affecting its networking products, prompting a fresh round of security updates. Two of the flaws sit in Cisco IOS XR, the operating system used in the firm's carrier-grade networking equipment, and were uncovered during what Cisco described as "a comprehensive internal security review." Their severity means affected organisations, including telecoms and large enterprises relying on this equipment, should treat patching as urgent, since successful exploitation could allow attackers to bypass authentication or manipulate device behaviour remotely.

The two IOS XR bugs, CVE-2026-20274 and CVE-2026-20279, both score 9.8 out of 10 on the CVSS scale; the former involves buffering and out-of-bounds write issues, while the latter concerns improper access control, including flawed certificate validation and missing authentication checks. Cisco also flagged several high-severity flaws rated between 8.2 and 8.8, and has released updated IOS XR versions to fix all of them. A third critical flaw, CVE-2026-20212, affects certain Nexus 9000 Series switches due to a faulty integration with Cisco's Silicon One processors, potentially letting an unauthenticated remote attacker gain root access; as no software fix yet exists, Cisco is advising affected customers to mitigate the risk using access control lists to block the exploitable network ports. The company says it has not observed any active exploitation of these vulnerabilities so far.

  • Cisco reveals three critical flaws in IOS XR and Nexus 9000 switches
  • Two IOS XR bugs score 9.8/10; patches are already available
  • Nexus 9000 flaw has no fix yet, only a mitigation via access controls

Americas Entertainment Software Technology TV World

Read the full article at the source →