CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] Cisco IOS XR: Multiple vulnerabilities enable unspecified attack

highCVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279
A remote, anonymous attacker can exploit multiple vulnerabilities in Cisco IOS XR to conduct an unspecified attack.

CSIRTS triage

What
Multiple vulnerabilities in Cisco IOS XR enable unspecified remote attacks from anonymous attackers.
Who is affected
Cisco IOS XR devices with remote network access.
Urgency
High severity; unspecified remote attack vectors from unauthenticated sources require urgent investigation.
Action
Review Cisco security advisories for IOS XR CVE-2026-20274 through CVE-2026-20280 and apply patches.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch IOS XR

Get an email when a new IOS XR advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-09-03
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3155

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-20274coverage & exploitation statusNVD · CVE.org
CVE-2026-20275coverage & exploitation statusNVD · CVE.org
CVE-2026-20276coverage & exploitation statusNVD · CVE.org
CVE-2026-20277coverage & exploitation statusNVD · CVE.org
CVE-2026-20278coverage & exploitation statusNVD · CVE.org
CVE-2026-20279coverage & exploitation statusNVD · CVE.org
CVE-2026-20280coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Cisco IOS XR

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories