ZeroHour
Organization

Info-Tech Research Group

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch

Cisco patched seven IOS XR vulnerabilities, two rated CVSS 9.8, allowing unauthenticated remote code execution and root access on carrier routers; no exploitation observed.

Cisco released fixes for seven internally discovered vulnerabilities in IOS XR, its Linux-based network operating system for carrier-grade routers. Two flaws, CVE-2026-20274 and CVE-2026-20279, are rated CVSS 9.8 (critical) and involve lifetime resource control issues that can enable unauthenticated remote code execution with root access; the other five are rated 8.2-8.8 and cover buffer overflows, access control failures, and out-of-bounds access. All IOS XR releases including IOS XR7 are affected regardless of configuration, no workarounds exist, and remediation requires software maintenance upgrades (SMUs) or fixed releases 26.2.2/26.3.1. Cisco says the flaws are not known to be actively exploited, but experts urge immediate patching of internet-facing and core routing systems, citing parallels with Salt Typhoon tradecraft.

What do CISOs need to rest easy about future AI risks?

IANS survey of 113 CISOs finds optimism about managing future AI security risks hinges more on organizational readiness and leadership support than current controls.

An IANS AI Security Survey of 113 CISOs fielded in April and May found 41% optimistic and 38% pessimistic about their organization's ability to manage AI security risks over the next 24 months. Six organizational signals—leadership understanding of AI risk, defined governance ownership, security team effectiveness with AI tools, CISO ownership of the AI-security budget, sustainable workloads, and staffing—separate confident CISOs from pessimistic ones. Interviewed analysts cautioned that these readiness signals measure self-assessed confidence rather than actual security, and recommended hands-on AI use by security teams plus governance of third-party models.

CSO Online · 8d agoIndustry

Related CVEs

  • Critical Improper Access Control in Cisco IOS XR Software
    CVE-2026-20279 covers one or more improper access control flaws (CWE-284) in Cisco IOS XR Software, discovered by Cisco's own engineering team during an internal security review and addressed in a bundled software hardening release. According to the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaws are remotely exploitable over the network with no authentication and no user interaction, and the 9.8 critical score reflects high impact to confidentiality, integrity, and availability, though the specific attack path is not detailed in the available data. A successful unauthenticated remote attacker would gain high-impact access to the affected device per the CVSS scoring, on networks running IOS XR, which is deployed primarily on Cisco's service-provider routing platforms. The fix was rolled into Cisco's coordinated September 2, 2026 advisory bundle, in which the IOS XR team consolidated patches for multiple internally discovered issues into a single update release, published alongside other Cisco fixes (including a separate critical Nexus 9000 issue). No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known; EPSS estimates the 30-day exploitation probability at roughly 0.3%.
    · Cisco IOS XR Softwarelarge
  • Critical Improper Resource Control Flaws in Cisco IOS XR Software
    CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days.
    · Cisco IOS XR Softwarelarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.