Junglewise Threat Intelligence

CVE-2026-20279: Cisco IOS XR Software improper access control

CVE-2026-20279 · Severity: critical · CVSS 9.8 · Published 2026-09-02

Technologies: Cisco IOS XR Software. Vendors: Cisco.

Executive brief

Cisco IOS XR Software is a core operating system used in enterprise routers and network infrastructure devices. Multiple internal security vulnerabilities related to improper access control and resource handling were discovered and addressed in a software hardening release. These flaws could allow attackers to bypass authentication, gain unauthorized access, or cause service disruption on affected network devices.

Technical details

This advisory addresses multiple vulnerability classes grouped under CVE-2026-20279, with the primary issue being improper access control (CWE-284), along with related issues in resource control lifetime (CWE-664), incorrect calculations (CWE-682), and insufficient input validation (CWE-707). The vulnerabilities were discovered through internal security review and affect all releases of Cisco IOS XR Software, including IOS XR7 (LNT), regardless of device configuration. The flaws require network access with no authentication or user interaction; a remote attacker can exploit these without privileges to achieve confidentiality, integrity, and availability impacts. Cisco has not reported active exploitation in the wild, but patches and SMUs (Service and Maintenance Upgrades) are available for affected software trains.

Affected products

  • Cisco IOS XR Software all releases including IOS XR7 (LNT)

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: advisory: Critical advisory published; Last updated 2026-09-17

References

Related threats