Executive brief
Cisco IOS XR Software, used in network routing and infrastructure equipment, contains an incorrect calculation vulnerability that could allow an unauthenticated remote attacker to compromise system integrity and availability. The vulnerability stems from integer overflow or underflow issues during internal security hardening review and affects all IOS XR releases. Cisco has released software updates to address this issue, with no workarounds available.
Technical details
CVE-2026-20275 represents a class of incorrect calculation vulnerabilities (CWE-682) in Cisco IOS XR Software, specifically covering integer overflow, integer underflow, and buffer size calculation errors. The vulnerability is remotely exploitable without authentication or user interaction, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). An attacker can exploit this to achieve high confidentiality, integrity, and availability impact. The issue was discovered during internal security review and is not known to be actively exploited. Cisco has released patched software versions and recommends customers upgrade to the fixed releases listed in the advisory or apply available SMUs.
Affected products
- Cisco IOS XR Software all releases including IOS XR7 (LNT)
Timeline
- 2026-09-02: disclosed
- 2026-09-17: other: Advisory last updated