ZeroHour
Cisco Security Advisoriespublished ()ingested

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

AI summary · glm-5.3-flash

Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.

Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.

  • IOS XR hardening release bundles six CVEs rated critical at CVSS 9.8
  • CVE-2026-20212: critical RCE in Nexus 9000 Silicon One switches
  • CVE-2026-20281: high-severity DoS in 9800/7800/8800 Series SIP phones, CVSS 7.5

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20212
Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration

CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.

Do: Inventory your Nexus 9000 fleet to identify Silicon One–integrated models and test whether TCP ports 43210/43211 are reachable in the default L3 VRF (e.g., nmap the management/default VRF or review interface and control-plane ACLs). Upgrade to the fixed software release listed in Cisco's advisory published September 2, 2026. As an interim mitigation, restrict access to ports 43210 and 43211 via ACLs and monitor for S1HAL process crashes or unexpected device reloads.

9.8<1%
  • Cisco Nexus 9000 Series Switches with Silicon One integration
large≈ tens of thousands of deployed switches plausibly in the affected subset (Silicon One–based Nexus 9000 models), of which likely only a few thousand have TCP…
CVE-2026-20274
Critical Improper Resource Control Flaws in Cisco IOS XR Software

CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days.

Do: Upgrade affected IOS XR devices to the security/hardening release bundled in Cisco's September 2, 2026 advisory batch, checking that advisory for the exact fixed release for your version train. Until patching is complete, restrict network reachability of IOS XR management and control planes to trusted operators, since the flaws require no authentication or user interaction. Organizations also running Cisco Nexus 9000 switching should review the separate, same-day NX-OS advisory for the unauthenticated root RCE reported in related coverage.

9.8
group max
<1%
  • Cisco IOS XR Software
large≈10^5 (on the order of ~100,000) internet-exposed IOS XR devices per public scan counts; total deployed fleet, including carrier-internal routers, is larger…
CVE-2026-20281
Unauthenticated Memory-Leak DoS in Cisco SIP Software for IP and Desk Phones

CVE-2026-20281 is a memory-management flaw (CWE-401) in the Cisco Session Initiation Protocol (SIP) Software running on the Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875, where HTTP packets are not properly released from memory. An unauthenticated, remote attacker can trigger it by sending a continuous stream of crafted HTTP packets to an affected phone, causing the device to consume memory without freeing it. A successful attack results in a denial-of-service condition on the handset that persists until an administrator manually reboots the device, with no confidentiality or integrity impact. Only phones registered to Cisco Unified Communications Manager (Unified CM) with Web Access enabled are exploitable, and Web Access is disabled by default, so a large share of deployments is likely unaffected. There is currently no evidence of exploitation, no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS estimates roughly a 0.3% chance of exploitation within 30 days.

Do: Inventory Unified CM registrations to identify phones running Cisco SIP Software and check whether Web Access is enabled; disabling Web Access on handsets that do not need it is an effective interim mitigation. Apply the fixed Cisco SIP Software release when Cisco publishes its advisory (scheduled for September 2, 2026, per its advance notification), and manually reboot any handset showing signs of memory exhaustion to restore service.

7.5<1%
  • Cisco Desk Phone 9800 Series running Cisco SIP Software
  • Cisco IP Phone 7800 Series running Cisco SIP Software
  • Cisco IP Phone 8800 Series running Cisco SIP Software
  • +1 more
massmillions of deployed handsets worldwide, with the directly exploitable subset (Unified CM-registered, Web Access enabled) plausibly in the hundreds of…
Full article

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco IOS XR Software Security Hardening Release: September 2026 CVE-2026-20277 CVE-2026-20278 CVE-2026-20280 CVE-2026-20279 CVE-2026-20276 CVE-2026-20275 CVE-2026-20274 Critical 9.8 Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability CVE-2026-20212 Critical 9.8 Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability CVE-2026-20281 High 7.5 Cisco Secure Email Secure/Multipurpose Internet Mail Extensions…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.