Cisco's Updated Security- Hardening Advisory for IOS XR Affects All Releases
Cisco has released an updated security-hardening advisory for its IOS XR platform, version 1.3, which affects all IOS XR releases, including IOS XR7 (LNT), regardless of configuration. The advisory groups the findings under seven CVE IDs and provides release-specific SMU information.
The company states that no workaround is available, making version identification crucial for remediation. TechRadar's September 4 report identifies CVE-2026-20274 and CVE-2026-20279 as critical IOS XR groups with a maximum CVSS score of 9.8.
To address the vulnerabilities, users must start by identifying the installed train, not configuration. This involves running 'show version' to record the complete release and hardware platform for each device.
Cisco's SMU documentation explains that an SMU is built for a particular release and component and is specific to the platform. Users must then locate the installed train in the fixed-release table, match the platform and affected functional areas to the listed SMU identifiers, and verify the active package set after activation.
The advisory's scope does not depend on an optional service being enabled, and disabling a protocol or changing an access list cannot establish that an IOS XR device is unaffected. The company emphasizes that operators needing packages for an unlisted release should open a TAC service request or contact their support organization.