CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5859

As cited

Copy frozen at (site build).

vulnerabilities

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

Cisco disclosed seven vulnerabilities across IOS XR and Nexus 9000 Series Switches following a comprehensive internal security review. Two critical flaws in IOS XR (CVE-2026-20274 and CVE-2026-20279) score 9.8 CVSS, while CVE-2026-20212 allows unauthenticated remote code execution with root privileges on ten Nexus 9000 models by exploiting open TCP ports 43210 and 43211. Cisco has published patched IOS XR versions and provided a mitigation tool for Nexus devices, recommending access control lists to block traffic to the vulnerable ports until a permanent fix arrives.

Why it matters: Network operators running Cisco IOS XR must apply patches immediately to remediate two critical 9.8-rated flaws. Nexus 9000 Series Switch operators must deploy access control list mitigations today to prevent unauthenticated remote code execution with root access, as no software patch exists yet.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

Cisco disclosed seven vulnerabilities across IOS XR and Nexus 9000 Series Switches following a comprehensive internal security review. Two critical flaws in IOS XR (CVE-2026-20274 and CVE-2026-20279) score 9.8 CVSS, while CVE-2026-20212 allows unauthenticated remote code execution with root privileges on ten Nexus 9000 models by exploiting open TCP ports 43210 and 43211. Cisco has published patched IOS XR versions and provided a mitigation tool for Nexus devices, recommending access control lists to block traffic to the vulnerable ports until a permanent fix arrives.

Why it matters: Network operators running Cisco IOS XR must apply patches immediately to remediate two critical 9.8-rated flaws. Nexus 9000 Series Switch operators must deploy access control list mitigations today to prevent unauthenticated remote code execution with root access, as no software patch exists yet.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary