Cisco has told every customer running IOS XR, the operating system on its carrier-class and core routers, that they need to patch. An internal security review by the IOS XR engineering team turned up multiple vulnerabilities across the entire release line, two of them in classes Cisco scores at 9.8 out of 10, and there are no workarounds. Cisco's hardening advisory was relayed by Hong Kong's CERT in a bulletin on 3 September.
The flaws were found in internal testing and Cisco says they are not known to be actively exploited. They affect all releases of Cisco IOS XR Software, including IOS XR7 (LNT) on the 8000 Series, NCS 1010, NCS 540L and NCS 5700 platforms, regardless of device configuration.
Seven CVEs, each standing for a bug class
Rather than a CVE per bug, Cisco grouped the findings by their Common Weakness Enumeration class and assigned one identifier to each group, with the score reflecting the single most severe bug inside it. Ordered by severity:
- CVE-2026-20274, CVSS 9.8: improper control of a resource through its lifetime, a class Cisco says covers stack and heap buffer overflows, out-of-bounds reads and writes, use-after-free, format string and resource exhaustion bugs.
- CVE-2026-20279, CVSS 9.8: improper access control, covering improper certificate validation, missing authentication for a critical function and missing or incorrect authorization.
- CVE-2026-20275, CVSS 8.8: incorrect calculation, including integer overflow and underflow.
- CVE-2026-20278, CVSS 8.8: improper neutralization, including command injection and unvalidated array indexes.
- CVE-2026-20280, CVSS 8.8: improper handling of exceptional conditions, including length inconsistencies and failing insecurely.
- CVE-2026-20276, CVSS 8.6: insufficient control flow management, covering reachable assertions and loops that never exit.
- CVE-2026-20277, CVSS 8.2: protection mechanism failure through insufficiently random values.
Cisco has not published which specific bug sits behind each score, and the advisory does not describe individual attack paths, so the class descriptions above are the full extent of what is known. The affected functional areas it lists are broad: BGP, IKE crypto, gRPC, IP SLA, IS-IS, MPLS and MPLS-TE, multicast, OSPF, segment routing, TCP Authentication Option and zero-touch provisioning, plus a fix that applies to every XR7 (LNT) platform.
This is the second such exercise in a month. In early August Cisco published a matching batch for IOS and IOS XE, also from an internal audit and also carrying two critical-rated CVEs. Hong Kong's CERT labels the IOS XR bulletin medium risk, which sits oddly beside Cisco's own scores.
Roughly 16 SMUs per release, or wait for 26.2.2
Remediation is heavier than a single upgrade. Cisco says there may be approximately 16 Software Maintenance Updates (SMUs) per release to cover the CWE groups, and customers must first move to a release that has SMUs available, then apply them. SMUs are available now for 7.3.2, 7.9.2 and 7.9.21, 7.10.2, 7.11.2 and 7.11.21, 24.2.2 and 24.2.21, 24.4.2, 25.2.21, 25.4.1 and 25.4.2, 26.1.2 and 26.2.1. SMUs for 24.1.2, 24.3.2, 25.1.2 and 25.2.2 are still to come. The first releases that will not need SMUs at all are 26.2.2 and 26.3.1, both future. Anyone on a release outside that table is directed to a TAC service request. Each SMU carries a CSC identifier that the advisory maps to a functional area, so operators can prioritize the protocols they actually run.
Routers running IOS XR sit at the core of service-provider and large-enterprise networks, exactly the kind of infrastructure a China-linked espionage crew was recently found living inside. Cisco found these bugs before anyone else did, as far as it knows. The window before that stops being true is the reason to start planning the SMU rollout now.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.