Executive brief
Cisco IOS XR Software contains multiple critical improper resource control vulnerabilities discovered during an internal security review. An unauthenticated attacker on the network can exploit these issues to cause a complete system compromise, including unauthorized access, data manipulation, or service disruption on affected network devices.
Technical details
CVE-2026-20274 addresses improper resource control issues (CWE-664) within Cisco IOS XR Software, covering multiple vulnerability classes including buffer overflows, out-of-bounds access, use-after-free, and insecure resource initialization. The vulnerabilities are network-accessible with no authentication or user interaction required, allowing remote code execution. The advisory indicates these issues were discovered internally and are not currently being actively exploited in the wild. Cisco has released software hardening updates; no workarounds are available, making patching the only mitigation path.
Affected products
- Cisco IOS XR Software All releases, including IOS XR7 (LNT)
Timeline
- 2026-09-02: disclosed: CVE-2026-20274 and related vulnerabilities disclosed
- 2026-09-02: patched: Software hardening releases available