Cisco searched for IOS XR bugs and found so many it rolled them into an update release

https://image.theregister.com/5294415.jpg?imageId=5294415&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

Cisco has warned its customers of three critical-rated flaws in its products.

Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit.

CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default.

CVE-2026-20279 is another 9.8-rated flaw. Cisco says it’s an improper access control problem that covers “improper certificate validation, missing authentication for critical function, missing authorization, and incorrect authorization.”

Cisco also spotted a trio of 8.8-rated flaws, plus another rated 8.6 and one more scored at 8.2

The company’s advisorysays the company found the flaws after “a comprehensive internal security review,” language that perhaps hints at Cisco dabbling with...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE

Read more