CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-20278

criticalCVSS 8.8covered by 5 sourcesfirst seen 2026-09-02
A remote, anonymous attacker can exploit multiple vulnerabilities in Cisco IOS XR to conduct an unspecified attack.

CSIRTS triage

What
Multiple vulnerabilities in Cisco IOS XR enable unspecified remote attacks from anonymous attackers.
Who is affected
Cisco IOS XR devices with remote network access.
Urgency
High severity; unspecified remote attack vectors from unauthenticated sources require urgent investigation.
Action
Review Cisco security advisories for IOS XR CVE-2026-20274 through CVE-2026-20280 and apply patches.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-20278

Get an email if CVE-2026-20278 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (5)

External references

NVD record for CVE-2026-20278

CVE.org record

Embed the live status

CVE-2026-20278 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-20278 status](https://www.csirts.com/badge/CVE-2026-20278)](https://www.csirts.com/cve/CVE-2026-20278)