CVE-2026-20277: Cisco IOS XR Software Security Hardening Release: September 2026
Published Sep 2, 2026
·Updated
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20277 are related to protection mechanism failure issues that are grouped under the Common Weakness Enumeration (CWE) CWE-693.
Affected Software
1 affected component
Cisco IOS XR Software Security Hardening Release
Event History
Sep 2, 2026
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates no privileges are required and no user interaction is required.
2
Can an attacker target affected systems over the network?
Yes. The CVSS vector lists network attack access with low attack complexity.