Skip to main content

Cisco Releases IOS XR Software Security Hardening Guidance

The critical advisory addresses multiple vulnerability classes affecting Cisco IOS XR deployments

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The critical advisory addresses multiple vulnerability classes affecting Cisco IOS XR deployments


Threat details

Introduction

Cisco has published a security hardening advisory for Cisco IOS XR Software following a comprehensive internal security review. The update addresses multiple vulnerability classes including improper control of resources, improper calculation, insufficient control flow management, protection mechanism failure, improper neutralization, improper access control, and improper check or handling of exceptional conditions vulnerabilities.

To streamline disclosure, Cisco grouped vulnerabilities according to their underlying Common Weakness Enumeration (CWE) category and assigned a single CVE identifier to each group. Several of the vulnerability classes have high severity ratings, with the most severe vulnerability carrying a CVSS score of 9.8.


Vulnerability Details

  • CVE-2026-20274 - 'Improper Control of a Resource Through its Lifetime' vulnerability - CVSSv3.1 score: 9.8
  • CVE-2026-20275 - 'Incorrect Calculation' vulnerability - CVSSv3.1 score: 8.8
  • CVE-2026-20276 - 'Insufficient Control Flow Management' vulnerability - CVSSv3.1 score: 8.6
  • CVE-2026-20277 - 'Protection Mechanism Failure' vulnerability - CVSSv3.1 score: 8.2
  • CVE-2026-20278 - 'Improper Neutralization' vulnerability - CVSSv3.1 score: 8.8
  • CVE-2026-20279 - 'Improper Access Control' vulnerability - CVSSv3.1 score: 9.8
  • CVE-2026-20280 - 'Improper Check or Handling of Exceptional Conditions' vulnerability - CVSSv3.1 score: 8.8

Remediation advice

Affected organisations are encouraged to review the Cisco cisco-sa-hardening-iosxr-qg64NcM advisory and apply relevant updates as soon as possible.



CVE Vulnerabilities

Last edited: 3 September 2026 2:58 pm