Cisco searched for IOS XR bugs and found so many it rolled them into an update release
Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix
Cisco has discovered and warned its customers about a total of five critical vulnerabilities in its products. Two of the flaws are present in the Cisco IOS XR operating system, which is used in the carrier-grade kit. The first flaw, CVE-2026-20274, has a CVSS score of 9.8 and is characterized by various buffering issues, potential out-of-bounds writes, and insecure default resource initialization.
The second flaw, CVE-2026-20279, also carries a 9.8 CVSS score and is attributed to improper access control, including improper certificate validation, missing authentication, missing authorization, and incorrect authorization.
Apart from these two major vulnerabilities, Cisco identified three additional 8.8-rated flaws and two others rated 8.6 and 8.2, respectively. The company came across these issues after conducting a thorough internal security review, possibly leveraging advanced tools such as Mythos or other bug-detection models.
In response to these findings, Cisco released updated versions of IOS XR and strongly encouraged customers to implement the changes. The second critical flaw, CVE-2026-20212, is particularly concerning due to its integration issue with Cisco's Silicon One networking processors. This vulnerability allows an unauthenticated, remote attacker to execute code with root privileges on certain Nexus 9000 Series Switches.
The exploitation of this vulnerability further enables the attacker to crash the S1HAL process, leading to device reboots.
Cisco recommends using infrastructure access control lists (iACLs) to mitigate the risk associated with this vulnerability by restricting management and control plane traffic to the affected device. Alternatively, iACLs can be used to block all TCP packets destined to a locally configured IP address with ports 43210 or 43211. While Cisco has not witnessed any attacks on these flaws, the potential for malicious use is growing, considering the advent of AI-powered threat generation.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.