Cisco Discloses Seven Vulnerabilities Affecting Networking Operating System
Cisco has disclosed seven vulnerabilities in its networking operating system and switches, including two critical severity bugs. The issues affect Cisco's IOS XR and impact various products, with the highest severity being CVE-2026-20274 and CVE-2026-20279.
CVE-2026-20274 is related to improper control of a resource through its lifetime via buffering issues, while CVE-2026-20279 involves incorrect certificate validation and missing authentication for critical functions. The bugs were discovered after an internal security review using Cisco's Antares AI model family.
In addition to the IOS XR vulnerabilities, Cisco flagged another bug affecting Silicon One integration in its Nexus 9000 data center switch. This issue could allow an unauthenticated remote attacker to execute code with root privileges due to exposed TCP ports and potentially cause the device to reload.