Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch
Cisco patched seven IOS XR vulnerabilities, two rated CVSS 9.8, allowing unauthenticated remote code execution and root access on carrier routers; no exploitation observed.
Cisco released fixes for seven internally discovered vulnerabilities in IOS XR, its Linux-based network operating system for carrier-grade routers. Two flaws, CVE-2026-20274 and CVE-2026-20279, are rated CVSS 9.8 (critical) and involve lifetime resource control issues that can enable unauthenticated remote code execution with root access; the other five are rated 8.2-8.8 and cover buffer overflows, access control failures, and out-of-bounds access. All IOS XR releases including IOS XR7 are affected regardless of configuration, no workarounds exist, and remediation requires software maintenance upgrades (SMUs) or fixed releases 26.2.2/26.3.1. Cisco says the flaws are not known to be actively exploited, but experts urge immediate patching of internet-facing and core routing systems, citing parallels with Salt Typhoon tradecraft.
- Two CVSS 9.8 flaws (CVE-2026-20274, CVE-2026-20279) permit unauthenticated RCE and root access on routers
- All IOS XR releases, including IOS XR7, are affected regardless of device configuration
- No workarounds available; remediation requires SMUs or future fixed releases 26.2.2 and 26.3.1
- Flaws found via internal testing, not known to be actively exploited yet
- Experts recommend prioritizing internet-facing and core routers and auditing supplier exposure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20274 +1 in the same advisory: …20279 | Critical Improper Resource Control Flaws in Cisco IOS XR Software CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days. Do: Upgrade affected IOS XR devices to the security/hardening release bundled in Cisco's September 2, 2026 advisory batch, checking that advisory for the exact fixed release for your version train. Until patching is complete, restrict network reachability of IOS XR management and control planes to trusted operators, since the flaws require no authentication or user interaction. Organizations also running Cisco Nexus 9000 switching should review the separate, same-day NX-OS advisory for the unauthenticated root RCE reported in related coverage. | 9.8 | <1% |
| large≈10^5 (on the order of ~100,000) internet-exposed IOS XR devices per public scan counts; total deployed fleet, including carrier-internal routers, is larger… |
Full article1,010 words · extracted from csoonline.com · click to collapse
Cisco is looking to get ahead of attackers with a new set of more than a half-dozen fixes, some of them critical, for its IOS XR Linux-based network operating system (OS).
As part of its regular testing, Cisco’s software engineering team flagged “multiple internally-discovered vulnerabilities,” the company said. These flaws could allow attackers to perform remote code execution (RCE) and gain root access on a router, thereby allowing them to intercept traffic. Other potential risks could include access control failures, buffer overflows, and out-of-bounds access.
Cisco said all IOS XR releases, including IOS XR7, are impacted, regardless of configuration. There are no known workarounds, but the company has released software updates.
Cisco emphasizes that, as of yet, the vulnerabilities are not known to be actively exploited.
IOS XR runs on some of the most critical routing infrastructure in a network, explained Erik Avakian, a technical counselor at Info-Tech Research Group. “The most serious vulnerabilities can potentially be exploited remotely with low attack complexity, without privileges or any user interaction,” he said. “That’s enough to warrant immediate attention and timely patching.”
Critical vulnerabilities allowing for ‘improper’ lifetime control issues
Two of the seven vulnerabilities identified by Cisco are rated 9.8 in severity (critical) based on the Common Vulnerability Scoring System (CVSS).
CVE-2026-20274 and CVE-2026-20279 both address lifetime resource control issues, such as inappropriate certificate validation, incorrect or missing authorization for critical functions, resource operation after release or expiration, out-of-bounds read or write, initialization of resources with insecure details, and resource allocation without throttling limits.
The five other vulnerabilities are rated between 8.8 and 8.2 (high severity). Those patches address incorrect network usage calculations (buffer size, overflow, underflow), improper checks or handling of exceptional conditions or inconsistencies, insufficient control flow management, and protection mechanism failures.
However, Cisco hasn’t explicitly said that every one of these issues can lead to RCE, Info-Tech’s Avakian noted. But access control issues could allow an attacker to reach resources they shouldn’t be able to, while memory-related flaws could cause system crashes, denial of service, or create a path toward code execution. If an attacker gained “meaningful control” of a device, that could result in network and business disruption, unapproved configuration changes, routing manipulation, or could pave the way for a broader attack, he said.
The two 9.8s are all about “getting access and persistence,” said David Shipley of Beauceron Security. Both RCE and root router access are in the Salt Typhoon playbook, he pointed out, adding, “worst case scenarios with some of these lower CVSS bugs is widespread network disruption and outages.”
These are critical flaws in carrier-grade equipment, and telecom companies worldwide should be paying attention, “because you can bet there is a bunch of nation-state hacking teams who are,” he noted.
What Cisco customers should do now
Customers can identify whether a device is running Cisco IOS XR by using the “show version” command, the company said. They should upgrade to a release with available software maintenance upgrades (SMUs), or targeted software patches that don’t require a full system upgrade, then apply appropriate SMUs.
Available SMUs cover software trains from various versions, starting with version 7.3. There may be up to 16 SMUs for each release, and customers requiring patches for other releases not identified by Cisco should contact their security support organization or open a Cisco service request, the company said. Future Cisco IOS XR Software releases (26.2.2 and 26.3.1) will be the first fixed releases not requiring SMUs.
Avakian advised prioritizing patching based on exposure and criticality. “Internet-facing and core routing systems keeping the network running should move to the front of the line,” he said. Another important step is to look closely at how these devices are being managed, and what’s actually exposed.
This makes the case for zero-trust principles: Restricting administrative access, applying and validating segmentation and access control lists (ACLs), and using out-of-band management “where practical,” Avakian said. Meanwhile, response teams should look for unexpected process crashes, configuration changes, unusual authentication activity, or unexplained routing changes.
There’s one additional consideration: It’s quite possible that even though an organization might not be running IOS XR directly, their telecom provider, MSP, or another critical partner might be, he noted.
“So, I’d be asking your various suppliers how they’re addressing it on their end: Whether they’re affected, if they’ve patched, and when remediation will be completed,” Avakian said. While the good news is that Cisco isn’t currently aware of public exploitation, the vulnerabilities are still public, there are no workarounds, and the highest-severity issues have characteristics attackers may try to exploit, he pointed out, “so timely patching is critical.”
AI heralding a whole new era of security
Interestingly, the total number of bugs addressed in the advisory is grouped around common weaknesses and use a CVE per weakness, instead of per bug, Shipley noted. Its bug count is quite the contrast with Microsoft’s, which has doubled the size of its Patch Tuesday update with all the bugs it’s fixing.
“Two global firms, both using AI, two different takes on communicating how many bugs were found that need to be fixed,” Shipley said.
“That doesn’t help transparency, “ he said. “But it does make [Cisco’s] products look like they have less bugs, which is more a marketing move than a security move.”
Also worth noting is that Cisco said the bugs were found during internal tests, using frontier AI, he added.
Avakian also noted the “new normal,” where AI is already beginning to find vulnerabilities much faster than humans can. That means that, while suppliers may find vulnerabilities faster, adversaries will also increasingly have access to the same types of capabilities and speed. “In many ways, it becomes an AI-against-AI race,” he said.
The challenge for CIOs and security leaders will now be how quickly they can understand their exposure, appropriately test the patches, and safely get fixes into production, Avakian said. “As AI accelerates exploit development while enterprise patching still takes weeks or months, the gap becomes increasingly unsustainable,” he pointed out.
This article originally appeared on Network World.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4219968/cisco-bundles-fixes-for-multiple-vulnerabilities-some-critical-into-one-patch-2.html