Junglewise Threat Intelligence

CVE-2026-20074: Cisco IOS XR Software DoS in IS-IS Multi-Instance Routing

CVE-2026-20074 · Severity: high · CVSS 7.4 · Published 2026-03-11

Technologies: Cisco IOS XR Software. Vendors: Cisco.

Executive brief

A vulnerability in Cisco's networking software for service provider routers could allow an attacker on the same local network to crash the routing process. This affects the IS-IS protocol, which is used to direct traffic across large networks. If exploited, the router would temporarily lose its ability to communicate with other parts of the network, leading to a service outage and potential disruption of customer internet or data services.

Technical details

The vulnerability exists in the IS-IS multi-instance routing feature of Cisco IOS XR Software due to improper input validation of ingress IS-IS packets (CWE-1287). An unauthenticated attacker who is Layer 2-adjacent to the target device can exploit this by first forming a routing adjacency and then sending specifically crafted IS-IS packets. A successful exploit triggers an unexpected restart of the IS-IS process, causing a temporary loss of routing information and connectivity to advertised networks. The vulnerability specifically affects devices with 'instance-id' configured under the IS-IS router process. Cisco has released software updates and suggests configuring IS-IS area authentication as a mitigation to prevent unauthorized adjacency formation.

Affected products

  • Cisco IOS XR Software 7.8.0 through 25.2.1, 25.3.0

Timeline

  • 2026-03-11: advisory: Initial public release by Cisco
  • 2026-03-11: patched: Fixed versions 25.2.2 and 25.3.1 released

References

Related threats