ZeroHour

CVE-2026-20276

large

Unauthenticated Remote DoS Flaws in Cisco IOS XR Software

CVSS 3.1
8.6 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-20276 covers a set of internally discovered vulnerabilities in Cisco IOS XR Software caused by insufficient control flow management (CWE-691), which Cisco addressed through software hardening releases following a comprehensive internal security review. The flaws are exploitable over the network by unauthenticated attackers with no user interaction or privileges required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). With no confidentiality or integrity impact but a high availability impact and changed scope, successful exploitation most likely causes a denial-of-service condition such as a device crash or process restart. Any organization running Cisco IOS XR — typically service providers and large enterprises operating carrier-grade routing infrastructure — is potentially affected, although the available data does not specify affected or fixed versions. There is no known exploitation in the wild, no public proof-of-concept, and EPSS assigns only a 0.3% 30-day exploitation probability, making this a schedule-patch rather than an emergency.

What to do: Inventory all IOS XR devices and consult Cisco's advisory (published alongside the September 2, 2026 advisory batch) for the exact affected and fixed releases before upgrading, since this data lists no version numbers; prioritize internet-facing and management-plane devices. As an interim mitigation, restrict SSH/Telnet and management-plane access to trusted networks with ACLs, given the unauthenticated, availability-only impact. With EPSS at 0.3% and no known exploitation or public PoC, patching in normal maintenance windows is a reasonable cadence.

Affected
Cisco IOS XR Software
Estimated exposure
large≈tens of thousands of deployed IOS XR systems (mostly in service-provider/enterprise core and edge networks; a smaller share directly internet-exposed) — IOS XR is Cisco's carrier-grade operating system for its service-provider routing portfolio and is widely deployed by ISPs and large enterprises; public internet scans typically surface tens of thousands of IOS XR management endpoints,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691.

Weakness
CWE-691
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco patches critical CVE-2026-20212 (CVSS 9.8) in Nexus 9000 switches allowing unauthenticated remote root code execution, plus IOS XR hardening release.

Cisco released fixes for CVE-2026-20212 (CVSS 9.8), a flaw in 10 Silicon One-based Nexus 9000 switch models that binds a service to an unrestricted IP, leaving TCP ports 43210/43211 reachable in the default Layer 3 VRF and allowing unauthenticated remote attackers to execute code as root; exploitation attempts can also crash the S1HAL process. 45 NX-OS releases (10.3(1) through 10.6(3s)) are affected, with mitigations including infrastructure ACLs, the Live Protect shield lp00031, and fixed releases identified via Cisco's Software Checker. Cisco simultaneously issued an IOS XR hardening release bundling 7 umbrella CVEs, two rated 9.8 (CVE-2026-20274 for memory-safety bugs and CVE-2026-20279 for access-control bugs), affecting all releases with SMUs available for 14 releases and upgrades required for 93 of 111 listed releases. No malicious exploitation was reported as of the September 2 disclosure.

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.

Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.