{
  "id": 5487074,
  "title": "Cisco searched for IOS XR bugs and found so many it rolled them into an update release",
  "url": "https://urgent.news/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-04T02:18:36.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410"
  },
  "original_language": "en",
  "account": "Cisco has discovered and warned its customers about a total of five critical vulnerabilities in its products. Two of the flaws are present in the Cisco IOS XR operating system, which is used in the carrier-grade kit. The first flaw, CVE-2026-20274, has a CVSS score of 9.8 and is characterized by various buffering issues, potential out-of-bounds writes, and insecure default resource initialization. The second flaw, CVE-2026-20279, also carries a 9.8 CVSS score and is attributed to improper access control, including improper certificate validation, missing authentication, missing authorization, and incorrect authorization.\n\nApart from these two major vulnerabilities, Cisco identified three additional 8.8-rated flaws and two others rated 8.6 and 8.2, respectively. The company came across these issues after conducting a thorough internal security review, possibly leveraging advanced tools such as Mythos or other bug-detection models.\n\nIn response to these findings, Cisco released updated versions of IOS XR and strongly encouraged customers to implement the changes. The second critical flaw, CVE-2026-20212, is particularly concerning due to its integration issue with Cisco's Silicon One networking processors. This vulnerability allows an unauthenticated, remote attacker to execute code with root privileges on certain Nexus 9000 Series Switches. The exploitation of this vulnerability further enables the attacker to crash the S1HAL process, leading to device reboots.\n\nCisco recommends using infrastructure access control lists (iACLs) to mitigate the risk associated with this vulnerability by restricting management and control plane traffic to the affected device. Alternatively, iACLs can be used to block all TCP packets destined to a locally configured IP address with ports 43210 or 43211. While Cisco has not witnessed any attacks on these flaws, the potential for malicious use is growing, considering the advent of AI-powered threat generation.",
  "summary": "Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Cisco searched for IOS XR bugs and found so many it rolled them into an update release",
        "url": "https://urgent.news/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-5490155",
        "published": "2026-09-04T02:18:36.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}