Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco discovered multiple security weaknesses in all versions of its IOS XR software used in many Cisco routers. These security issues were found during Cisco's own internal tests, and no active attacks using these vulnerabilities are known. Cisco has released software updates to fix these issues and strongly recommends customers upgrade. No temporary workarounds are available, so updating is the only way to address these problems.

Published 11/9/2026, 3:53:35 pmVerified 11/9/2026, 9:04:24 pmRevision 8
Cisco critical network security advisory visual

In plain language

What this advisory means

Cisco discovered multiple security weaknesses in all versions of its IOS XR software used in many Cisco routers. These security issues were found during Cisco's own internal tests, and no active attacks using these vulnerabilities are known. Cisco has released software updates to fix these issues and strongly recommends customers upgrade. No temporary workarounds are available, so updating is the only way to address these problems.

Technical explanation

How the issue affects the environment

The Cisco IOS XR software contains multiple security vulnerabilities spanning several Common Weakness Enumerations (CWEs), including improper resource lifetime control (e.g., buffer overflows, use-after-free), incorrect calculations (integer overflows), insufficient control flow management, protection mechanism failures (such as use of insufficiently random values), improper input neutralization, improper access control (missing or incorrect authorization), and improper handling of exceptional conditions. These issues potentially allow attackers to execute arbitrary code, cause denial of service, or bypass security controls. Cisco identified these vulnerabilities during an internal security review and issued updates starting with releases 26.2.2 and 26.3.1, along with Software Maintenance Updates (SMUs) for numerous affected release trains and platforms. The vulnerabilities affect all releases of IOS XR software, including IOS XR7 (LNT) versions, across all device configurations. No workarounds are available, making software upgrade the required remediation.

Operational impact

Why teams should care

Exploitation of these vulnerabilities could allow attackers to compromise Cisco IOS XR devices, potentially leading to loss of confidentiality, integrity, and availability of network infrastructure. This could disrupt network operations and impact business continuity. Since no workarounds exist, organizations must apply software updates promptly to mitigate these critical risks.

Immediate action

Upgrade Cisco IOS XR software to versions 26.2.2 or 26.3.1 where fixes are included, or apply the appropriate Software Maintenance Updates (SMUs) for your platform and release train as listed in the advisory. Consult Cisco Technical Assistance Center if unsure about upgrade paths or specific SMUs required.

Affected and fixed releases

Affected versionsAll releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration
Fixed versionsCisco IOS XR Software releases 26.2.2, 26.3.1, and applicable SMUs for other release trains and platforms

Temporary risk reduction

No workarounds are available for these vulnerabilities. The only way to remediate is by applying the software updates provided by Cisco.

Evidence and validation checklist

  • Cisco internal security review identified vulnerabilities.
  • Cisco advisory published detailing vulnerabilities and fixes.
  • List of CWEs and CVEs assigned and described.
  • Release of fixed software versions and SMUs.
  • Statement of no known active exploitation.
  • No workarounds available.

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
Cisco IOS XR Software Security Hardening | Advisory | QCS