Cisco bundles fixes for critical IOS XR and Nexus 9000 flaws uncovered by internal review
Cisco disclosed multiple critical flaws found during an internal security review: CVE-2026-20274 and CVE-2026-20279 (CVSS 9.8) allow unauthenticated remote code execution with root access on IOS XR carrier routers, and CVE-2026-20212 allows unauthenticated…
Cisco rolled fixes for multiple vulnerabilities found in a comprehensive internal security review into a single update release. In IOS XR, its Linux-based network operating system for carrier-grade routers, Cisco patched seven vulnerabilities. Two are rated critical at CVSS 9.8 (CVE-2026-20274 and CVE-2026-20279) and involve lifetime resource control issues that can enable unauthenticated remote code execution with root access; the other five are rated CVSS 8.2–8.8 and cover buffer overflows, access control failures, and out-of-bounds access. All IOS XR releases, including IOS XR7, are affected regardless of configuration, no workarounds exist, and remediation requires software maintenance upgrades (SMUs) or fixed releases 26.2.2 and 26.3.1. Separately, CVE-2026-20212, a critical flaw in the Silicon One integration used by certain Nexus 9000 switches, lets unauthenticated remote attackers execute code with root privileges by reaching TCP ports 43210 and 43211 in the default Layer 3 VRF; it affects ten Nexus 9000 models and is currently mitigated only by infrastructure ACLs (iACLs), with no permanent software fix available yet. Cisco says it has not observed attacks against these flaws. Experts nonetheless urge immediate patching of internet-facing and core routing systems, citing parallels with Salt Typhoon tradecraft. Source note: The Register (Sep 4) reported the IOS XR flaws as fixed in newly released versions, while CSO Online (Sep 9) describes remediation as SMUs or fixed releases 26.2.2/26.3.1.
- CVE-2026-20212 (critical): unauthenticated remote code execution with root privileges on certain Nexus 9000 Series Switches; the flaw resides in the Silicon One integration (SOCRadar, Sep 4).
- CVE-2026-20212 is reachable via TCP ports 43210 and 43211 in the default Layer 3 VRF and affects ten Nexus 9000 models (The Register, Sep 4).
- Nexus 9000 flaw has no software fix yet; only infrastructure ACL (iACL) mitigations are available (The Register, Sep 4).
- CVE-2026-20274 and CVE-2026-20279 (both CVSS 9.8, critical): IOS XR lifetime resource control issues enabling unauthenticated remote code execution with root access on carrier routers.
- Seven IOS XR vulnerabilities were patched in total; the other five are rated CVSS 8.2–8.8 (buffer overflows, access control failures, out-of-bounds access) (CSO Online, Sep 9).
- All IOS XR releases, including IOS XR7, are affected regardless of device configuration; no workarounds exist (CSO Online, Sep 9).
- IOS XR remediation requires SMUs or fixed releases 26.2.2 and 26.3.1 (CSO Online, Sep 9); The Register (Sep 4) described the IOS XR flaws as fixed in newly released versions — sources differ slightly on fix availability framing.
- All flaws were found via Cisco's internal review/testing; Cisco says no exploitation has been observed or is known to be active (all three reports).
Coverage timelineoldest first · each row is one article
- · 13d agoCisco searched for IOS XR bugs and found so many it rolled them into an update release
The Register · Security· 65
Cisco patched three critical flaws, including CVE-2026-20212 unauthenticated remote root code execution in Nexus 9000 switches; no exploitation observed yet.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20212 | Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days. Do: Inventory your Nexus 9000 fleet to identify Silicon One–integrated models and test whether TCP ports 43210/43211 are reachable in the default L3 VRF (e.g., nmap the management/default VRF or review interface and control-plane ACLs). Upgrade to the fixed software release listed in Cisco's advisory published September 2, 2026. As an interim mitigation, restrict access to ports 43210 and 43211 via ACLs and monitor for S1HAL process crashes or unexpected device reloads. | 9.8 | <1% |
| large≈ tens of thousands of deployed switches plausibly in the affected subset (Silicon One–based Nexus 9000 models), of which likely only a few thousand have TCP… | ||
| CVE-2026-20274 +1 in the same advisory: …20279 | Critical Improper Resource Control Flaws in Cisco IOS XR Software CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days. Do: Upgrade affected IOS XR devices to the security/hardening release bundled in Cisco's September 2, 2026 advisory batch, checking that advisory for the exact fixed release for your version train. Until patching is complete, restrict network reachability of IOS XR management and control planes to trusted operators, since the flaws require no authentication or user interaction. Organizations also running Cisco Nexus 9000 switching should review the separate, same-day NX-OS advisory for the unauthenticated root RCE reported in related coverage. | 9.8 | <1% |
| large≈10^5 (on the order of ~100,000) internet-exposed IOS XR devices per public scan counts; total deployed fleet, including carrier-internal routers, is larger… |