Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco has performed a thorough internal security review of its IOS XR software, identifying multiple vulnerabilities that could allow an attacker to take control, disrupt services, or gain unauthorized access. No evidence shows these flaws are being exploited yet. Cisco urges all users to install released software updates promptly, as no other temporary fixes exist.

Published 2/9/2026, 9:53:32 pmVerified 2/9/2026, 10:06:02 pmRevision 2
Cisco critical network security advisory visual

In plain language

What this advisory means

Cisco has performed a thorough internal security review of its IOS XR software, identifying multiple vulnerabilities that could allow an attacker to take control, disrupt services, or gain unauthorized access. No evidence shows these flaws are being exploited yet. Cisco urges all users to install released software updates promptly, as no other temporary fixes exist.

Technical explanation

How the issue affects the environment

The Cisco IOS XR Software engineering team discovered several critical security weaknesses during internal testing, grouped into categories including improper resource control (CWE-664), incorrect calculations (CWE-682), insufficient control flow management (CWE-691), protection mechanism failures (CWE-693), improper input neutralization (CWE-707), and improper access control (CWE-284). These issues can lead to memory corruption (such as buffer overflows), privilege escalation, unauthorized command execution, and denial of service, all with a maximum CVSS v3.1 base score of 9.8. Cisco has released software maintenance updates (SMUs) and plans future fixed releases to remediate these vulnerabilities without available workarounds.

Operational impact

Why teams should care

Exploitation of these vulnerabilities could allow attackers to disrupt enterprise network operations, gain unauthorized access, and compromise confidential information. This could result in operational downtime, data breaches, service interruptions, and reputational damage for organizations relying on Cisco IOS XR devices.

Immediate action

Cisco strongly recommends all affected customers upgrade to the fixed software releases or apply the appropriate Security Maintenance Updates (SMUs) listed in the advisory to remediate these vulnerabilities.

Affected and fixed releases

Affected versionsAll releases of Cisco IOS XR Software including IOS XR7 (LNT) releases
Fixed versionsCisco IOS XR Software with SMUs applied starting from versions 7.3.2, 7.9.2, 7.10.2, 7.11.2, 24.2.2, 24.4.2, 25.2.21, 25.4.2, 26.1.2, 26.2.1 and future releases 26.2.2, 26.3.1

Temporary risk reduction

No workarounds are available to address these vulnerabilities; applying the updates is the only remediation.

Evidence and validation checklist

  • Cisco official security advisory published on September 2, 2026
  • Summary states vulnerabilities from internal security review, no known active exploitation
  • Detailed CVE and CWE mappings with CVSS 3.1 scores up to 9.8
  • List of affected Cisco IOS XR versions including XR7 (LNT)
  • Fixed versions provided with SMUs and upcoming fixed releases
  • Explicit mention of no available workarounds
  • Cisco PSIRT confirmation of no active exploitation or public announcements

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source