CVE-2026-20274 CVE-2026-20279 CVE-2026-20275 CVE-2026-20278 CVE-2026-20280 CVE-2026-20276 CVE-2026-20277
Cisco IOS XR Software security hardening release addresses multiple internally discovered vulnerabilities (September 2026)
Cisco IOS XR Software is affected by multiple internally discovered vulnerabilities fixed in the September 2026 security hardening release. Two are critical and reachable without credentials; no workarounds exist. Apply the release and restrict exposure.
What happened
Cisco has published a security hardening release for IOS XR Software following an internal security review. The release addresses seven internally discovered vulnerabilities. Two of them are rated critical with a CVSS score of 9.8 and can be reached over the network without credentials or user interaction; successful exploitation could give an attacker full control of the affected device, compromising confidentiality, integrity and availability. The remaining five are rated high. They are reachable over the network or an adjacent network, and some require low privileges, with impacts ranging from unauthorised modification and availability loss to full compromise. Cisco PSIRT has stated that it is not aware of any public announcements or malicious use of the vulnerabilities described in this advisory.
Who is affected
Cisco lists the following IOS XR Software versions as affected: 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.90, 7.0.1, 7.0.90 and 7.1.1. Any deployment running one of these versions should treat itself as in scope. The data available here does not list specific fixed version numbers; Cisco has indicated that a fix is available.
What to do now
- Inventory affected devices: confirm whether any of the listed IOS XR versions are in use.
- Apply the September 2026 security hardening release. The data available here does not include specific fixed version numbers, so obtain the applicable release from Cisco's advisory or your Cisco support channel.
- There are no workarounds that address these vulnerabilities, so treat patching as the primary remediation.
- Until patching is complete, restrict network access to affected devices, particularly management interfaces, to trusted networks only.
- After patching, verify that the affected versions are no longer present and review whether access controls on the devices remain appropriate.
How to detect it
Cisco has not published indicators of compromise for these vulnerabilities. Detection should begin with accurate inventory of affected IOS XR versions and a review of which management or service interfaces are reachable from untrusted networks. After patching, confirm that devices no longer report the affected versions.
Beyond the patch
For an advisory with no workarounds, the first job is knowing where every affected IOS XR device sits and which parts of the network can reach it. Our Virtual CISO Services (vCISO) can help build and maintain that exposure view, so network-reachable services are found before a hardening release becomes urgent. Because this is vendor software embedded in your routing estate, Supply Chain Defense & Third-Party Risk helps track these advisories and plan remediation alongside your other third-party risk obligations.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-20274 Cisco IOS XR Software | 6.5.29 7.0.1 6.5.26 6.5.25 6.5.28 6.5.90 7.1.1 7.0.90 | No fixed version listed yet |
| CVE-2026-20279 Cisco IOS XR Software | 6.5.29 7.0.1 6.5.26 6.5.25 6.5.28 6.5.90 7.1.1 7.0.90 | No fixed version listed yet |
| CVE-2026-20275 Cisco IOS XR Software | 6.5.29 7.0.1 6.5.26 6.5.25 6.5.28 6.5.90 7.1.1 7.0.90 | No fixed version listed yet |
| CVE-2026-20278 Cisco IOS XR Software | 6.5.29 7.0.1 6.5.26 6.5.25 6.5.28 6.5.90 7.1.1 7.0.90 | No fixed version listed yet |
| CVE-2026-20280 Cisco IOS XR Software | 6.5.29 7.0.1 6.5.26 6.5.25 6.5.28 6.5.90 7.1.1 7.0.90 | No fixed version listed yet |
| CVE-2026-20276 Cisco IOS XR Software | 6.5.29 7.0.1 6.5.26 6.5.25 6.5.28 6.5.90 7.1.1 7.0.90 | No fixed version listed yet |
| CVE-2026-20277 Cisco IOS XR Software | 6.5.29 7.0.1 6.5.26 6.5.25 6.5.28 6.5.90 7.1.1 7.0.90 | No fixed version listed yet |
References
Vendor advisory
CVE
- CVE-2026-20274 — cve.org
- CVE-2026-20274 — NVD
- CVE-2026-20279 — cve.org
- CVE-2026-20279 — NVD
- CVE-2026-20275 — cve.org
- CVE-2026-20275 — NVD
- CVE-2026-20278 — cve.org
- CVE-2026-20278 — NVD
- CVE-2026-20280 — cve.org
- CVE-2026-20280 — NVD
- CVE-2026-20276 — cve.org
- CVE-2026-20276 — NVD
- CVE-2026-20277 — cve.org
- CVE-2026-20277 — NVD