Cisco patches three critical vulnerabilities as part of 'comprehensive internal security review'
- Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)
- Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution
- No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC
Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.
The company detailed its findings in two advisories published on the same day - September 2.
In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE