Cisco Patches Critical IOS XR Flaws Across Core Network Platforms

Server Security

Cisco has released security updates for seven vulnerability groups affecting every release of IOS XR, including two critical groups rated 9.8 out of 10. The company says there are no workarounds, leaving software upgrades and platform-specific maintenance updates as the required response.

The vulnerabilities were disclosed in a security advisory first published on September 2, 2026, following an internal review of the carrier-grade operating system. Cisco updated the advisory again on September 9 as additional Software Maintenance Updates, or SMUs, became available.

IOS XR runs routers used in telecommunications networks, internet backbones, data-center interconnects and large enterprise environments. The breadth of the affected software makes the release relevant to operators whose network availability depends on routing, MPLS, segment-routing and control-plane services.

Current status

All IOS XR releases, including IOS XR7, are affected regardless of device configuration. Cisco reports no known malicious exploitation, but no workaround is available.

Two critical vulnerability groups

The two highest-severity classifications are CVE-2026-20274 and CVE-2026-20279. Both carry a maximum CVSS score of 9.8.

CVE-2026-20274 groups defects involving improper control of resources throughout their lifetime. Cisco’s advisory associates the category with underlying weakness types including buffer overflows, out-of-bounds reads and writes, use-after-free conditions, externally controlled format strings and insecure resource initialization.

CVE-2026-20279 covers improper access-control defects, including missing authentication or authorization, incorrect authorization and improper certificate validation. The assigned network attack vector indicates that the most serious underlying issue can be reached remotely without authentication or user interaction.

Five additional vulnerability groups are included in the release. Three have maximum CVSS scores of 8.8, one is rated 8.6 and another is rated 8.2. They cover incorrect calculations, insufficient control-flow management, protection-mechanism failures, improper input neutralization and unsafe handling of exceptional conditions.

Every IOS XR release is in scope

Cisco states that all releases of IOS XR Software and IOS XR7, also known as LNT, are vulnerable regardless of configuration. IOS XR7 platforms include Cisco 8000 Series routers and several Network Convergence System products, including the NCS 1010, NCS 540L and NCS 5700 families.

The affected functional areas vary by release and platform. Cisco’s update matrix includes BGP, OSPF, IS-IS, MPLS, MPLS traffic engineering, multicast, IPv4 and IPv6 segment routing, gRPC, IKE, IP-SLA, TCP Authentication Option and Zero Touch Provisioning.

The company grouped internally discovered defects by their highest-level Common Weakness Enumeration category. Each CVE can therefore represent several underlying problems, while the listed CVSS value reflects the most severe issue within that group rather than every defect carrying the same impact.

Cisco publishes fixes but no workaround

Cisco has published fixed software and SMUs for supported release trains. The precise update path depends on the installed release, hardware platform and enabled functional areas, meaning operators must use the matrix in the official Cisco security advisory rather than applying a single universal package.

The vendor says future IOS XR releases 26.2.2 and 26.3.1 will be the first releases to contain the fixes without requiring SMUs. Existing deployments may require multiple maintenance packages to cover the relevant software components.

Cisco’s Product Security Incident Response Team said it was not aware of public announcements or malicious exploitation of the vulnerabilities when the advisory was updated. The defects were found during internal testing that used established testing processes as well as frontier AI models.

What network operators should do now

Operators should identify every IOS XR and IOS XR7 device, record its active release and platform, and compare that inventory with Cisco’s fixed-software and SMU tables. Because there is no workaround, compensating controls do not replace installation of the applicable updates.

  • Confirm the installed IOS XR train and whether the platform runs IOS XR7.
  • Map enabled routing and management functions to Cisco’s affected-area matrix.
  • Upgrade to a supported release with available SMUs and apply every relevant package.
  • Schedule redundant routers separately to avoid removing parallel network paths at the same time.
  • Verify the running software and SMU state after each maintenance window.

For carriers, hosting providers and data-center operators, the main operational risk is the size of the patching scope. Router maintenance must be coordinated around redundant links, routing convergence and customer traffic, while the absence of a workaround limits the value of delaying updates.

Cisco first published the advisory on September 2, 2026. The fixed-software information was updated through September 9, 2026.