ZeroHour

CVE-2026-20278

large

Improper Neutralization Flaws in Cisco IOS XR Software (CWE-707)

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-20278 covers a set of improper neutralization weaknesses (CWE-707) in Cisco IOS XR Software that Cisco's engineering team discovered during an internal security review and addressed in dedicated software hardening releases. The issues are remotely exploitable over the network by an attacker who holds valid low-privileged credentials on the device (CVSS vector AV:N/AC:L/PR:L/UI:N), with no user interaction required. Successful exploitation yields high impact to the confidentiality, integrity, and availability of the affected component, consistent with broad compromise of the impacted device functionality. Any operator running the affected IOS XR releases is in scope; IOS XR is Cisco's carrier-grade router operating system, though specific affected and fixed version ranges are not provided in the available data. There is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so it is not currently known to be exploited in the wild.

What to do: Upgrade IOS XR devices to the fixed hardening releases specified in Cisco's September 2026 advisory (exact release numbers are not included in the available data). In the interim, restrict SSH, NETCONF, and gRPC management access to trusted management networks and limit which low-privileged accounts can reach vulnerable devices, since exploitation requires valid credentials. Note that the widely reported Nexus 9000 unauthenticated root RCE is a separate NX-OS advisory and does not affect this IOS XR issue.

Affected
Cisco IOS XR Software
Estimated exposure
large~10,000-100,000 IOS XR router deployments plausibly in scope (large carrier-router installed base; exact counts unpublished) — IOS XR powers Cisco's core and edge carrier router lines (such as the ASR 9000, NCS, and 8000 series), which have a very large global installed base, but exploitation requires low-privileged credentials and only a subset of devices have…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20278 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707.

Weakness
CWE-707
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco patches critical CVE-2026-20212 (CVSS 9.8) in Nexus 9000 switches allowing unauthenticated remote root code execution, plus IOS XR hardening release.

Cisco released fixes for CVE-2026-20212 (CVSS 9.8), a flaw in 10 Silicon One-based Nexus 9000 switch models that binds a service to an unrestricted IP, leaving TCP ports 43210/43211 reachable in the default Layer 3 VRF and allowing unauthenticated remote attackers to execute code as root; exploitation attempts can also crash the S1HAL process. 45 NX-OS releases (10.3(1) through 10.6(3s)) are affected, with mitigations including infrastructure ACLs, the Live Protect shield lp00031, and fixed releases identified via Cisco's Software Checker. Cisco simultaneously issued an IOS XR hardening release bundling 7 umbrella CVEs, two rated 9.8 (CVE-2026-20274 for memory-safety bugs and CVE-2026-20279 for access-control bugs), affecting all releases with SMUs available for 14 releases and upgrades required for 93 of 111 listed releases. No malicious exploitation was reported as of the September 2 disclosure.

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.

Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.