Cisco Issues Patches for Eight Critical IOS XR Vulnerabilities
Cisco has issued patches to address eight vulnerabilities in its IOS XR operating system, including three critical ones. The company's 'comprehensive internal security review' revealed several flaws that could be exploited by attackers without authentication or user interaction.
The three critical vulnerabilities affect all releases of Cisco IOS XR Software and are tracked as CVE-2026-20274, CVE-2026-20279, and CVE-2026-20212. The latter is an improper access control vulnerability that can lead to unauthorized execution of crafted input.
Successful exploitation of CVE-2026-20212 could cause the S1HAL process to crash, leading to a device reload. Cisco Nexus 9000 Series Switches with Silicon One ASICs are particularly vulnerable and require patches or iACL workarounds.