CVE-2026-20280: Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates that exploitation is possible over the network with low privileges and does not require user interaction.
What could successful exploitation affect?
The reported CVSS impact is high for confidentiality, integrity, and availability, with the impact remaining within the affected security authority.
Is a specific affected IOS XR version or default configuration identified?
No affected versions, fixed versions, or default-configuration conditions are provided in the available data.