Sploitus Multiple CVEs Discovered in Cisco IOS XR Software
Article Content
- •Cisco identified multiple high-severity vulnerabilities in IOS XR Software.
- •CVE-2026-20279 and CVE-2026-20274 have CVSS scores of 9.8, indicating critical risks.
- •Cisco has released patches and recommends immediate updates for affected systems.
Cisco's internal security review identified several vulnerabilities in IOS XR Software, including CVE-2026-20279 and CVE-2026-20274, both rated at CVSS 9.8. These vulnerabilities involve improper access control and lifecycle management issues. Cisco has released patches for these vulnerabilities, which affect various versions of IOS XR Software. As of now, there is no evidence of active exploitation of these vulnerabilities. The vulnerabilities were published on September 2, 2026, and Cisco has provided remediation guidance for affected customers. The company emphasizes the importance of timely updates to mitigate risks associated with these flaws.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-20274 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cisco IOS XR Vulnerabilities Require Immediate Patching Cisco has released a patch addressing multiple vulnerabilities in its IOS XR network operating system, affecting all IOS XR releases, including IOS XR7. The vulnerabilities, tracked under CVEs including CVE-2026-20274 and CVE-2026-20279, could allow remote code execution (RCE) and root access on routers, posing…
Critical RCE Vulnerability in Cisco Nexus 9000 Switches Disclosed On September 2, 2026, Cisco disclosed a critical vulnerability (CVE-2026-20212) affecting its Nexus 9000 Series Switches equipped with Silicon One ASICs. This flaw allows unauthenticated remote attackers to execute code with root privileges via accessible TCP ports 43210 and 43211 in the default Layer 3 virtual…