Skip to content

Release roundup

Cisco Week 36 of 2026: three critical IOS XR and NX-OS flaws lead 11 CVEs

Critical 9.8 Vendor: Cisco 11 CVEs in scope Published

Cisco week 36 of 2026 covers 11 CVEs: 3 critical, 6 high and 2 medium. No exploited or CISA KEV entries. Prioritise the NX-OS Silicon One remote code execution flaw and the IOS XR hardening release, then SIP and Secure Email fixes.

The release at a glance

Cisco's week 36 of 2026 release contains 11 CVEs in scope for readers. The severity mix is three critical, six high and two medium. None of the CVEs is listed as exploited or appears in CISA's Known Exploited Vulnerabilities catalogue. Product-wise, seven affect Cisco IOS XR Software, two affect Cisco Secure Email, one affects Cisco NX-OS Software and one affects Cisco Session Initiation Protocol (SIP) Software.

The most urgent item is CVE-2026-20212, a critical remote code execution flaw in the Silicon One hardware abstraction layer for Cisco Nexus 3000 and 9000 Series Switches. The two other critical CVEs, CVE-2026-20274 and CVE-2026-20279, are part of the Cisco IOS XR Software September 2026 hardening release, along with five high-rated IOS XR items.

What matters most

Cisco NX-OS Software — CVE-2026-20212. A critical remote code execution vulnerability in the Silicon One integration. It is reachable over the network without authentication on TCP ports 43210 and 43211 in the default L3 VRF, and successful exploitation could allow root-privilege code execution or a device reload. Cisco PSIRT says it is not aware of public announcements or malicious use. This is the first item to examine because it combines a critical score with unauthenticated network access on widely deployed switch platforms.

Cisco IOS XR Software — September 2026 hardening release. Seven CVEs form this release's largest group: CVE-2026-20274 (improper resource control, CVSS 9.8), CVE-2026-20279 (improper access control, CVSS 9.8), CVE-2026-20275 (incorrect calculation, CVSS 8.8), CVE-2026-20280 (improper exceptional-condition handling, CVSS 8.8), CVE-2026-20278 (improper neutralisation, CVSS 8.8), CVE-2026-20276 (insufficient control-flow management, CVSS 8.6) and CVE-2026-20277 (protection mechanism failure, CVSS 8.2). The critical-rated entries are unauthenticated network flaws; the high-rated ones include network and adjacent-vector issues. These matter because IOS XR runs core routing and transport infrastructure. Cisco has separate advisories for each of these CVEs.

Patch in this order

  1. Start with Cisco NX-OS Software for CVE-2026-20212. Because it is an unauthenticated network-accessible remote code execution issue, patch affected Nexus 3000 and 9000 Series Switches before any other item.
  1. Move to the Cisco IOS XR Software hardening release. Apply the fix for the two critical CVEs, CVE-2026-20274 and CVE-2026-20279, first, then address the five high-rated hardening CVEs: CVE-2026-20275, CVE-2026-20280, CVE-2026-20278, CVE-2026-20276 and CVE-2026-20277. Treat internet-facing IOS XR devices as the highest priority within this group.
  1. Patch Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 running SIP Software for CVE-2026-20281. The risk is unauthenticated remote denial of service on phones registered to Unified CM with Web Access enabled; Web Access is disabled by default.
  1. Update Cisco Secure Email for CVE-2026-20354 and CVE-2026-20355. These medium-rated S/MIME plaintext-recovery issues have a public announcement but no known malicious use. Patch after the critical and high-items are underway.
  1. Complete the remaining Cisco update cycle for any affected devices not already covered, following your normal change management.

Beyond the patch

For a release like this, where the highest risks are unauthenticated network-reachable IOS XR and NX-OS flaws, the immediate question is which devices are exposed. Virtual CISO Services can help scope that exposure before the patch window closes. If code execution or credential abuse is suspected later, Managed Detection & Response can provide the detection and investigation trail.

Every CVE in this release

CVEProductSeverity
CVE-2026-20212Cisco NX-OS SoftwareCritical 9.8Advisory →
CVE-2026-20274Cisco IOS XR SoftwareCritical 9.8Advisory →
CVE-2026-20279Cisco IOS XR SoftwareCritical 9.8Advisory →
CVE-2026-20275Cisco IOS XR SoftwareHigh 8.8Advisory →
CVE-2026-20280Cisco IOS XR SoftwareHigh 8.8Advisory →
CVE-2026-20278Cisco IOS XR SoftwareHigh 8.8Advisory →
CVE-2026-20276Cisco IOS XR SoftwareHigh 8.6Advisory →
CVE-2026-20277Cisco IOS XR SoftwareHigh 8.2Advisory →
CVE-2026-20281Cisco Session Initiation Protocol (SIP) SoftwareHigh 7.5
CVE-2026-20354Cisco Secure EmailMedium 5.9
CVE-2026-20355Cisco Secure EmailMedium 5.9

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.