Known vulnerabilities in Cisco IOS XR

Software: Cisco IOS XR
Software CPE: cpe:2.3:o:cisco_systems:cisco_ios_xr:*:*:*:*:*:*:*:*
Total vulnerabilities: 112
Public exploits: 1
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco IOS XR Cisco IOS XR is affected by 112 known vulnerabilities: 1 critical, 25 high, 44 medium, 41 low Critical High Medium Low

Vulnerabilities (112)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146765 - Incorrect Calculation
CVE-2026-20275
CWE-682 High
No
No
26.2.2, 26.3.1 02.09.2026 SB2026090283
#VU146766 - Insufficient Control Flow Management
CVE-2026-20276
CWE-691 High
No
No
26.2.2, 26.3.1 02.09.2026 SB2026090283
#VU146767 - Protection Mechanism Failure
CVE-2026-20277
CWE-693 High
No
No
26.2.2, 26.3.1 02.09.2026 SB2026090283
#VU146768 - Improper Neutralization
CVE-2026-20278
CWE-707 High
No
No
26.2.2, 26.3.1 02.09.2026 SB2026090283
#VU146769 - Improper Access Control
CVE-2026-20279
CWE-284 High
No
No
26.2.2, 26.3.1 02.09.2026 SB2026090283
#VU146770 - Improper Check or Handling of Exceptional Conditions
CVE-2026-20280
CWE-703 High
No
No
26.2.2, 26.3.1 02.09.2026 SB2026090283
#VU146764 - Improper control of a resource through its lifetime
CVE-2026-20274
CWE-664 High
No
No
26.2.2, 26.3.1 02.09.2026 SB2026090283
#VU124029 - Permissions, Privileges, and Access Controls
CVE-2026-20046
CWE-264 Low
No
No
25.2.2 16.03.2026 SB2026031632
#VU124028 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-20040
CWE-78 Low
No
No
24.2.1, 24.2.2, 24.2.11, 24.2.20, 24.2.21, 24.3.1, 24.3.2, 24.3.20, 24.3.30, 24.4.1, 24.4.2, 24.4.10, 24.4.15, 24.4.30, 25.1.1, 25.1.2, 25.1.30, 25.2.1, 25.2.2, 25.2.15, 25.2.30, 25.3.1, 25.4.1, 26.1.1 16.03.2026 SB2026031632
#VU123907 - Improper Validation of Specified Type of Input
CVE-2026-20074
CWE-1287 Medium
No
No
25.1.30, 25.2.2, 25.3.1, 25.4.1, 26.1.1 12.03.2026 SB2026031202
#VU123906 - Improper Cleanup on Thrown Exception
CVE-2026-20118
CWE-460 Medium
No
No
7.9.2 CSCws66900, 7.10.2 CSCws66892, 7.11.2 CSCws66900, 7.11.21 CSCws66900, 24.1.2 CSCws66892, 24.2.2 CSCws66892, 24.2.21 CSCws36724, 24.2.21 CSCws66900, 24.3.2 CSCws66900, 24.4.2 CSCws66900 12.03.2026 SB2026031201
#VU116120 - Heap-based Buffer Overflow
CVE-2025-20363
CWE-122 Critical
No
No
- 25.09.2025 SB2025092573
SB2025092574
SB2025092575
#VU115158 - Improper Access Control
CVE-2025-20159
CWE-284 Medium
No
No
24.2.21, 24.3.1, 25.1.1, 25.1.2, 25.2.1 11.09.2025 SB2025091127
#VU115157 - Resource exhaustion
CVE-2025-20340
CWE-400 Medium
No
No
24.2.21, 25.1.2, 25.2.1 11.09.2025 SB2025091126
#VU115156 - Improper Verification of Cryptographic Signature
CVE-2025-20248
CWE-347
No
No
24.2.21, 24.3.20, 24.3.30, 24.4.2, 24.4.30, 25.1.1, 25.1.2, 25.2.1 11.09.2025 SB2025091125
#VU108835 - Improper input validation
CVE-2025-20154
CWE-20 High
No
No
24.3.2, 24.3.20, 24.4.1, 24.4.2, 24.4.10, 25.1.1 09.05.2025 SB2025050934
#VU105699 - Permissions, Privileges, and Access Controls
CVE-2025-20177
CWE-264 Low
No
No
7.11.21, 24.2.2, 24.2.20, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031338
#VU105698 - Memory corruption
CVE-2025-20115
CWE-119 High
No
No
24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031337
#VU105693 - Improper input validation
CVE-2025-20146
CWE-20 High
No
No
24.4.1 13.03.2025 SB2025031336
#VU105692 - Improper Access Control
CVE-2025-20144
CWE-284 Medium
No
No
6.2.1, 7.11.2, 7.11.21, 24.1.1, 24.1.2, 24.2.1, 24.2.2, 24.2.11, 24.2.20, 24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031335


Showing elements 1 - 20 out of 112