Skip to content
Multiple CVEs Discovered in Cisco IOS XR Software

Multiple CVEs Discovered in Cisco IOS XR Software

First seen 12 Sep 2026, 18:12 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 12, 2026 at 18:55 UTC
  • Cisco identified multiple high-severity vulnerabilities in IOS XR Software.
  • CVE-2026-20279 and CVE-2026-20274 have CVSS scores of 9.8, indicating critical risks.
  • Cisco has released patches and recommends immediate updates for affected systems.

Cisco's internal security review identified several vulnerabilities in IOS XR Software, including CVE-2026-20279 and CVE-2026-20274, both rated at CVSS 9.8. These vulnerabilities involve improper access control and lifecycle management issues. Cisco has released patches for these vulnerabilities, which affect various versions of IOS XR Software. As of now, there is no evidence of active exploitation of these vulnerabilities. The vulnerabilities were published on September 2, 2026, and Cisco has provided remediation guidance for affected customers. The company emphasizes the importance of timely updates to mitigate risks associated with these flaws.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-02
CVE-2026-20280 published
Cisco disclosed CVE-2026-20280, a vulnerability with CVSS 8.8 related to improper exception handling.
www.twcert.org.tw
2026-09-02
CVE-2026-20279 published
CVE-2026-20279 was published, highlighting an improper access control vulnerability rated CVSS 9.8.
www.twcert.org.tw
2026-09-02
CVE-2026-20278 published
CVE-2026-20278, rated CVSS 8.8, was disclosed for improper handling of vulnerabilities.
www.twcert.org.tw
2026-09-02
CVE-2026-20275 published
Cisco published CVE-2026-20275, a vulnerability involving calculation errors with CVSS 8.8.
www.twcert.org.tw
2026-09-02
CVE-2026-20274 published
CVE-2026-20274 was published, indicating improper control during the resource lifecycle with CVSS 9.8.
www.twcert.org.tw

More articles in this cluster (2)

Following this threat?

Track CVE-2026-20274 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed