Executive brief
Cisco IOS XR Software is the operating system used in Cisco routers and other network infrastructure devices. These vulnerabilities represent multiple security flaws discovered during internal review that could allow attackers to compromise system integrity, availability, or confidentiality. No active exploitation has been reported, but patches are now available.
Technical details
CVE-2026-20277 is grouped under CWE-693 (Protection Mechanism Failure) and represents one of seven related vulnerabilities discovered during Cisco's internal security review. The advisory groups multiple vulnerability classes (CWE-284, CWE-664, CWE-682, CWE-691, CWE-693, CWE-703, CWE-707) including resource lifetime control issues, incorrect calculations, insufficient control flow management, and improper neutralization. All releases of Cisco IOS XR Software are affected, including IOS XR7 (LNT). The attack vector is network-based with no authentication required (CVSS 9.8 base for the most critical variant). Cisco has released software updates and SMUs to address these vulnerabilities; no workarounds are available.
Affected products
- Cisco IOS XR Software All releases including IOS XR7 (LNT)
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Software updates and SMUs released