ZeroHour

CVE-2026-20280

large

Improper Exception-Condition Handling (CWE-703) in Cisco IOS XR Software

CVSS 3.1
8.8 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-20280 is a group of multiple internally discovered flaws in Cisco IOS XR Software, Cisco's operating system for carrier-grade routing platforms, all involving improper checking or handling of exceptional conditions (CWE-703). They were found by the IOS XR engineering team during a comprehensive internal security review and are addressed via software hardening releases announced in Cisco's September 2, 2026 advisory batch. Per the CVSS vector, an attacker with valid low-privileged credentials can trigger the flaw over the network without user interaction (AV:N/AC:L/PR:L/UI:N) and gain high-impact effects on the device's confidentiality, integrity, and availability (C:H/I:H/A:H); the exact impact mechanism is not detailed in the available data. Organizations operating IOS XR-based routing infrastructure — typically service providers, telecom operators, and large enterprises — are affected. There is no evidence of exploitation in the wild, no known public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.3% (19th percentile); the related Nexus 9000 critical RCE headline refers to a separate advisory published in the same batch, not this CVE.

What to do: Upgrade IOS XR devices to the hardening/maintenance releases Cisco published with the September 2, 2026 advisory, checking the official Cisco advisory for the correct fixed release per platform since version numbers are not in the available data. Because exploitation requires valid low-privileged network access, restrict management-plane services (SSH, Telnet, and related interfaces) to trusted users and networks, and audit for any shared or low-privilege accounts reachable from untrusted zones. Prioritize internet-facing or shared-management routers for patching and monitor the Cisco PSIRT page for updates.

Affected
Cisco IOS XR Software
Estimated exposure
large≈100,000+ IOS XR devices deployed worldwide (service-provider/enterprise routing installed base), with internet-exposed management instances a much smaller… — Estimated from deployment patterns of Cisco's carrier-grade routing installed base (platforms that run IOS XR such as the ASR 9000, NCS, and 8000 series), which commonly number in the tens to hundreds of thousands of units globally; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.

Weakness
CWE-703
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco patches critical CVE-2026-20212 (CVSS 9.8) in Nexus 9000 switches allowing unauthenticated remote root code execution, plus IOS XR hardening release.

Cisco released fixes for CVE-2026-20212 (CVSS 9.8), a flaw in 10 Silicon One-based Nexus 9000 switch models that binds a service to an unrestricted IP, leaving TCP ports 43210/43211 reachable in the default Layer 3 VRF and allowing unauthenticated remote attackers to execute code as root; exploitation attempts can also crash the S1HAL process. 45 NX-OS releases (10.3(1) through 10.6(3s)) are affected, with mitigations including infrastructure ACLs, the Live Protect shield lp00031, and fixed releases identified via Cisco's Software Checker. Cisco simultaneously issued an IOS XR hardening release bundling 7 umbrella CVEs, two rated 9.8 (CVE-2026-20274 for memory-safety bugs and CVE-2026-20279 for access-control bugs), affecting all releases with SMUs available for 14 releases and upgrades required for 93 of 111 listed releases. No malicious exploitation was reported as of the September 2 disclosure.

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.

Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.