ZeroHour

CVE-2026-20275

large

Incorrect Calculation Vulnerabilities in Cisco IOS XR Software

CVSS 3.1
8.8 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-20275 tracks multiple internally discovered incorrect-calculation issues (CWE-682) in Cisco IOS XR Software, found during Cisco's internal security review and addressed through dedicated software hardening releases. According to the CVSS 3.1 vector (AV:A/AC:L/PR:N/UI:N), an unauthenticated attacker positioned on an adjacent network segment could trigger the flaw with no user interaction or privileges required. Successful exploitation carries high-impact consequences for confidentiality, integrity, and availability (CVSS 8.8, High), though the advisory summary does not detail the precise mechanism or the exact attacker gain. Any deployment running Cisco IOS XR Software is potentially affected; defenders should consult Cisco's September 2, 2026 advisory publication for exact affected releases and fixed versions, which are not specified in the available data. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists, and EPSS assigns only a 0.2% probability of exploitation within 30 days.

What to do: Watch for Cisco's September 2, 2026 advisory publication for CVE-2026-20275 and, once released, apply the IOS XR software hardening releases it identifies, since exact affected and fixed versions are not yet specified in the available data. In the meantime, inventory IOS XR devices and restrict unauthenticated access to the network segments adjacent to their management and forwarding planes. Given the low EPSS score and absence of public PoCs, this can be scheduled within normal patch cycles unless Cisco raises severity or discloses active exploitation.

Affected
Cisco IOS XR Software
Estimated exposure
large≈100,000+ systems (IOS XR powers Cisco's carrier-grade service-provider router installed base, though only devices reachable by unauthenticated… — IOS XR is the operating system across Cisco's service-provider router portfolio (e.g., ASR 9000, NCS, and 8000 series families), whose cumulative carrier and large-enterprise installed base is on the order of 100k+ systems, and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-682.

Weakness
CWE-682
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco patches critical CVE-2026-20212 (CVSS 9.8) in Nexus 9000 switches allowing unauthenticated remote root code execution, plus IOS XR hardening release.

Cisco released fixes for CVE-2026-20212 (CVSS 9.8), a flaw in 10 Silicon One-based Nexus 9000 switch models that binds a service to an unrestricted IP, leaving TCP ports 43210/43211 reachable in the default Layer 3 VRF and allowing unauthenticated remote attackers to execute code as root; exploitation attempts can also crash the S1HAL process. 45 NX-OS releases (10.3(1) through 10.6(3s)) are affected, with mitigations including infrastructure ACLs, the Live Protect shield lp00031, and fixed releases identified via Cisco's Software Checker. Cisco simultaneously issued an IOS XR hardening release bundling 7 umbrella CVEs, two rated 9.8 (CVE-2026-20274 for memory-safety bugs and CVE-2026-20279 for access-control bugs), affecting all releases with SMUs available for 14 releases and upgrades required for 93 of 111 listed releases. No malicious exploitation was reported as of the September 2 disclosure.

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.

Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.