Cisco patches three critical vulnerabilities as part of 'comprehensive internal security review'
Date:
Fri, 04 Sep 2026 13:55:00 +0000
Description:
A total of eight flaws were fixed, none of which were exploited in the wild.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Cisco patched eight IOS XR flaws, including three critical (CVE202620274, CVE202620279, CVE202620212) Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC Cisco patched eight vulnerabilities affecting its IOS XR operating system , including three critical-severity ones. It urged its customers to apply the patches as soon
as possible, even though it stressed that there is no evidence any of these were abused in the wild.
The company detailed its findings in two advisories published on the same day - September 2. In the first one, it disclosed seven vulnerabilities,
including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences. Latest Videos From TechRadar Watch full video here: Fixes and mitigations These flaws, along
with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.
The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload, Cisco explained. You may like US and security allies warn Russian attacks on critical infrastructure are ramping up TP-Link router owners update now 15 flaws patched to stop hackers hijacking your devices Check Point says VPN attacks caused by Qilin ransomware group
This bug affects Cisco Nexus 9000 Series Switches if they include a Silicon One ASIC, the company stressed. A possible workaround is to use
infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.
Via The Register Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
or sponsors By submitting your information you agree to the Terms &
Conditions and Privacy Policy and are aged 16 or over. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/cisco-patches-three-critical-vulnerabil ities-as-part-of-comprehensive-internal-security-review
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)