Jump to the main content block

【Vulnerability Alert】Cisco IOS XR Software Contains Five Critical Cybersecurity Vulnerabilities

publish date : 2026-09-11 update date : 2026-09-11

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026090708095858 Publication Time 2026-09-04 09:12:32
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-04 09:12:32
Impact Level Low  
[Subject]
【Vulnerability Alert】Cisco IOS XR Software Contains Five Critical Cybersecurity Vulnerabilities
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000004

The Cisco IOS XR Software development team discovered multiple security vulnerabilities during an internal security review and has completed remediation. Currently, there is no evidence indicating that these vulnerabilities are being actively exploited. To assist customers in deploying security updates in a timely manner and simplify the vulnerability disclosure process, Cisco has publicly released the relevant vulnerability information and remediation recommendations.

CVE-2026-20280 (CVSS: 8.8) is an Improper Check or Handling of Exceptional Conditions vulnerability.

CVE-2026-20279 (CVSS: 9.8) is an Improper Access Control vulnerability.

CVE-2026-20278 (CVSS: 8.8) is an Improper Handling vulnerability.

CVE-2026-20275 (CVSS: 8.8) is a Calculation Error vulnerability, including incorrect buffer size calculations, integer overflow, and other issues.

CVE-2026-20274 (CVSS: 9.8) is an Improper Control of a Resource Through its Lifetime vulnerability.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

For the detailed list of affected products and versions, please refer to the official website announcement.

[Recommended Actions]

Apply the patches according to the remediation instructions released on the official website.

[Reference]

 https://www.twcert.org.tw/tw/cp-169-11186-faaa9-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: