Executive brief
Cisco IOS XR Software contains multiple vulnerabilities in exception condition handling discovered during an internal security review. These flaws could allow an unauthenticated attacker to compromise network device availability, integrity, or confidentiality. Cisco has released software updates to address the issues, with no workarounds currently available.
Technical details
CVE-2026-20280 is one of seven vulnerabilities grouped under a software hardening release addressing improper checking or handling of exceptional conditions (CWE-703). The vulnerabilities span multiple weakness categories including buffer overflows, integer calculation errors, insufficient control flow management, weak randomization, input validation flaws, and access control bypasses. These issues were discovered during internal testing and are not known to be actively exploited. The vulnerabilities affect all releases of Cisco IOS XR Software, including IOS XR7 (LNT), and are reachable over the network without requiring authentication. Cisco has released patched software versions and SMUs (Software Maintenance Updates) to remediate the issues.
Affected products
- Cisco IOS XR Software all releases
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Software hardening releases with fixes available