Cisco Discloses Critical Flaws in IOS XR and Nexus 9000 Switches
Cisco has disclosed seven vulnerabilities affecting its networking operating system, IOS XR, and the Silicon One integration in the Nexus 9000 data center switch. The two critical flaws, CVE-2026-20274 and CVE-2026-20279, stem from improper resource control via buffering issues and incorrect certificate validation with missing authentication, respectively.
The vulnerabilities were discovered during an internal security review by Cisco. A separate bug, CVE-2026-20212, affects the Silicon One integration in the Nexus 9000 switch. This vulnerability could allow an unauthenticated, remote attacker to execute code with root privileges by exploiting exposed TCP ports 43210 and 43211 in the default Layer 3 virtual routing and forwarding.
Cisco advises users to upgrade affected Nexus 9000 switches to a fixed Cisco NX-OS release to mitigate these risks. The company has not specified which releases are affected or when the fixes will be available.