Posting Date: 2026/09/07
【Vulnerability Alert】5 Critical Security Vulnerabilities Found in Cisco IOS XR Software
- Subject: 【Vulnerability Alert】5 Critical Security Vulnerabilities Found in Cisco IOS XR Software
- Description:
- Forwarded security alert TWCERTCC-200-202609-00000004 from Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC).
- The Cisco IOS XR Software development team discovered multiple security vulnerabilities during an internal security review and has completed patches for them. Currently, there is no evidence indicating that these vulnerabilities are being actively exploited. To assist customers in deploying security updates in a timely manner and to simplify the vulnerability disclosure process, Cisco has published information regarding the relevant vulnerabilities and remediation recommendations.
- CVE-2026-20280 (CVSS: 8.8): Improper Check or Handling of Exceptional Conditions.
- CVE-2026-20279 (CVSS: 9.8): Improper Access Control Vulnerability.
- CVE-2026-20278 (CVSS: 8.8): Improper Handling Vulnerability.
- CVE-2026-20275 (CVSS: 8.8): Incorrect Calculation, including buffer size calculation errors and integer overflow.
- CVE-2026-20274 (CVSS: 9.8): Improper Control of Generation of Code or Control of Resource Lifecycle.
- Affected Platforms:
- For the detailed list of affected products and versions, please refer to the official website announcement.
- Recommendations:
- Apply patches according to the solutions released on the official website.
- References:
Computer and Communication Center
Network System Division