Cisco Releases IOS XR Software Security Hardening Guidance
The critical advisory addresses multiple vulnerability classes affecting Cisco IOS XR deployments
Summary
The critical advisory addresses multiple vulnerability classes affecting Cisco IOS XR deployments
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has published a security hardening advisory for Cisco IOS XR Software following a comprehensive internal security review. The update addresses multiple vulnerability classes including improper control of resources, improper calculation, insufficient control flow management, protection mechanism failure, improper neutralization, improper access control, and improper check or handling of exceptional conditions vulnerabilities.
To streamline disclosure, Cisco grouped vulnerabilities according to their underlying Common Weakness Enumeration (CWE) category and assigned a single CVE identifier to each group. Several of the vulnerability classes have high severity ratings, with the most severe vulnerability carrying a CVSS score of 9.8.
Vulnerability Details
- CVE-2026-20274 - 'Improper Control of a Resource Through its Lifetime' vulnerability - CVSSv3.1 score: 9.8
- CVE-2026-20275 - 'Incorrect Calculation' vulnerability - CVSSv3.1 score: 8.8
- CVE-2026-20276 - 'Insufficient Control Flow Management' vulnerability - CVSSv3.1 score: 8.6
- CVE-2026-20277 - 'Protection Mechanism Failure' vulnerability - CVSSv3.1 score: 8.2
- CVE-2026-20278 - 'Improper Neutralization' vulnerability - CVSSv3.1 score: 8.8
- CVE-2026-20279 - 'Improper Access Control' vulnerability - CVSSv3.1 score: 9.8
- CVE-2026-20280 - 'Improper Check or Handling of Exceptional Conditions' vulnerability - CVSSv3.1 score: 8.8
Remediation advice
Affected organisations are encouraged to review the Cisco cisco-sa-hardening-iosxr-qg64NcM advisory and apply relevant updates as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 3 September 2026 2:58 pm