SB2026090283 - Multiple vulnerabilities in Cisco IOS XR



SB2026090283 - Multiple vulnerabilities in Cisco IOS XR

Published: September 2, 2026

Security Bulletin ID SB2026090283
CSH Severity
High
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-20274)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.

The vulnerability exists due to improper control of a resource through its lifetime in Cisco IOS XR Software when processing network input. A remote attacker can send crafted input to execute arbitrary code or cause a denial of service.


2) Incorrect calculation (CVE-ID: CVE-2026-20275)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.

The vulnerability exists due to incorrect calculation in Cisco IOS XR Software when processing network input. A remote attacker can send crafted input to execute arbitrary code or cause a denial of service.


3) Insufficient Control Flow Management (CVE-ID: CVE-2026-20276)

CWE-ID: CWE-691 - Insufficient Control Flow Management

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to insufficient control flow management in Cisco IOS XR Software when processing network input. A remote attacker can send crafted input to cause a denial of service.

The covered issues include reachable assertion and loop with unreachable exit condition.


4) Protection mechanism failure (CVE-ID: CVE-2026-20277)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass protection mechanisms.

The vulnerability exists due to protection mechanism failure in Cisco IOS XR Software when processing security-sensitive operations. A remote attacker can leverage insufficiently random values to bypass protection mechanisms.

The covered issues include use of insufficiently random values.


5) Improper Neutralization (CVE-ID: CVE-2026-20278)

CWE-ID: CWE-707 - Improper Neutralization

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands or code.

The vulnerability exists due to improper neutralization in Cisco IOS XR Software when processing crafted input. A remote attacker can send crafted input to execute arbitrary commands or code.

The covered issues include improper neutralization of special elements used in a command, improper neutralization of directives in dynamically evaluated code, and improper validation of array indexes, quantities, positions, or offsets in input.


6) Improper access control (CVE-ID: CVE-2026-20279)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication or authorization and gain unauthorized access.

The vulnerability exists due to improper access control in Cisco IOS XR Software when handling access to critical functions or protected resources. A remote attacker can access critical functionality without proper authorization to bypass authentication or authorization and gain unauthorized access.

The covered issues include improper certificate validation, missing authentication for a critical function, missing authorization, and incorrect authorization.


7) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-20280)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.

The vulnerability exists due to improper check or handling of exceptional conditions in Cisco IOS XR Software when processing crafted input. A remote attacker can send crafted input to execute arbitrary code or cause a denial of service.

The covered issues include improper handling of length parameter inconsistency and not failing securely.


Remediation

Install update from vendor's website.