Cisco searched for IOS XR bugs and found so many it rolled them into an update release
2026-09-04 10:18Cybersecurity🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
4mentions
SummaryAI generated
Cisco has released IOS XR security updates aimed at fixing three high-risk vulnerabilities. CVE-2026-20274 and CVE-2026-20279 both have a score of 9.8, involving buffer overflow and authentication deficiencies respectively; another vulnerability, CVE-2026-20212, due to improper integration of Silicon One processors, poses a risk of remote code execution for Nexus 9000 series switches. This vulnerability was discovered during an internal security review. Cisco recommends that users use Infrastructure Access Control Lists (iACLs) to restrict management traffic or deny TCP packets from specific ports to mitigate the risk. A permanent fix for CVE-2026-20212 has not been released yet, but auxiliary download tools are available. The company states that no related attacks have been observed, but warns that hackers may exploit AI to create malware.