Cisco Patches Eight Critical Vulnerabilities in IOS XR Operating System
Cisco has patched eight critical vulnerabilities in its IOS XR operating system, including three that can be exploited without authentication.
The company disclosed the flaws as part of a 'comprehensive internal security review', urging customers to apply the patches as soon as possible.
The three critical-severity vulnerabilities, tracked as CVE-2026-20274, CVE-2026-20279, and CVE-2026-20212, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software.
Cisco explained that the third flaw allows attackers to send crafted input that could be executed as code without root privileges, potentially causing the S1HAL process to crash and the device to reload.