cisco-sa-notice-f2SiMFxl: Cisco Advance Notification for Publication of September 2, 2026, Security Advisories
On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories:Cisco Security AdvisoryCVE IDSecurity Impact RatingCVSS Base ScoreCisco IOS XR Software Security Hardening Release: September 2026CVE-2026-20277CVE-2026-20278CVE-2026-20280CVE-2026-20279CVE-2026-20276CVE-2026-20275CVE-2026-20274Critical9.8Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution VulnerabilityCVE-2026-20212Critical 9.8Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service VulnerabilityCVE-2026-20281High7.5Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption VulnerabilitiesCVE-2026-20355CVE-2026-20354Medium5.9To remediate the vulnerabilities that were disclosed on September 2, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories.For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery.
Affected Software
Event History
Frequently Asked Questions
Which products are expected to receive vulnerability advisories and fixed software releases?
The September 2, 2026 advisories are expected to cover Desk Phone 9800, 7800, 8800, and 8875 Series Software; IOS XR Software through a security hardening release; Nexus 9000 Series Switches Silicon One; and Secure Email.
What remediation action is currently recommended?
Customers should review the advisories once published and upgrade to the fixed software versions identified there to fully remediate the disclosed vulnerabilities.