Forwarded security alert TWCERTCC-200-202609-00000004 from Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC).
The Cisco IOS XR Software development team discovered multiple security vulnerabilities during an internal security review and has completed patches for them. Currently, there is no evidence indicating that these vulnerabilities are being actively exploited. To assist customers in deploying security updates in a timely manner and to simplify the vulnerability disclosure process, Cisco has published information regarding the relevant vulnerabilities and remediation recommendations.
CVE-2026-20280 (CVSS: 8.8): Improper Check or Handling of Exceptional Conditions.
CVE-2026-20279 (CVSS: 9.8): Improper Access Control Vulnerability.
CVE-2026-20278 (CVSS: 8.8): Improper Handling Vulnerability.
CVE-2026-20275 (CVSS: 8.8): Incorrect Calculation, including buffer size calculation errors and integer overflow.
CVE-2026-20274 (CVSS: 9.8): Improper Control of Generation of Code or Control of Resource Lifecycle.