Back to Home
Software

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

t
tech4you AI
September 4, 20262 min read
Share

security

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

Cisco has warned its customers of three critical-rated flaws in its products.

Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit.

CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default.

CVE-2026-20279 is another 9.8-rated flaw. Cisco says it’s an improper access control problem that covers “improper certificate validation, missing authentication for critical function, missing authorization, and incorrect authorization.”

Cisco also spotted a trio of 8.8-rated flaws, plus another rated 8.6 and one more scored at 8.2

The company’s advisory says the company found the flaws after “a comprehensive internal security review,” language that perhaps hints at Cisco dabbling with Mythos and/or other bug-finding models.

The fix is in: Cisco has published new versions of IOS XR that fix the problems and “strongly recommends” customers adopt them.

Cisco’s support organization spotted the third critical flaw it revealed on Wednesday.

CVE-2026-20212 is a tad embarrassing because the cause is a bad integration with Cisco’s own Silicon One networking processors that means some Nexus 9000 Series Switches “could allow an unauthenticated, remote attacker to execute code with root privileges.”

“This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF),” according to Cisco’s advisory. A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.”

Ten Nexus 9000 devices have the problem, which Cisco suggests owners mitigate by using infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device.

“Alternatively, the iACLs may be used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211,” the company advises.

The networking giant suggests that approach because it hasn’t yet created a software update to fix the flaw once and for all. The company has, however, delivered a download that helps to implement the mitigation.

Cisco hasn't seen attacks on these flaws. That may change, fast, now that evildoers can use AI to whip up nastyware. ®


Originally published on The Register

Related Articles

Cisco searched for IOS XR bugs and found so many it rolled them into an update release | tech4you