In plain language
What this advisory means
On September 2, 2026, Cisco released security advisories for multiple products including Cisco IOS XR software, Cisco Nexus 9000 Series Switches, Cisco desk phones, and Cisco Secure Email. These advisories address critical vulnerabilities such as remote code execution and denial of service. Cisco strongly recommends customers upgrade to the indicated fixed software versions to protect their systems.
Technical explanation
How the issue affects the environment
Cisco's Product Security Incident Response Team (PSIRT) published advisories for several vulnerabilities. The Cisco IOS XR Software vulnerabilities include multiple critical issues with a CVSS score of 9.8 that affect system security hardening. The Cisco Nexus 9000 Series Switches Silicon One has a critical remote code execution vulnerability (CVE-2026-20212) also rated 9.8 CVSS. Cisco Desk Phone 9800 Series and related IP and Video phones have a high-severity denial of service vulnerability (CVE-2026-20281) with a 7.5 CVSS base score. Additionally, Cisco Secure Email has medium severity vulnerabilities (CVE-2026-20354 and CVE-2026-20355) related to cipher text decryption in Secure/Multipurpose Internet Mail Extensions (S/MIME). Cisco recommends upgrading to fixed versions as specified in the advisories to mitigate these risks.
Operational impact
Why teams should care
Exploitation of the critical vulnerabilities in Cisco IOS XR software and Nexus switches could allow attackers to execute arbitrary code remotely, potentially compromising network integrity and availability. Denial of service vulnerabilities in Cisco IP phones could disrupt communication services. Medium-risk vulnerabilities in Cisco Secure Email might allow unauthorized decryption of ciphertext, risking sensitive email data exposure. Organizations using these products should prioritize upgrades to maintain security and operational continuity.
Immediate action
Cisco strongly recommends that customers upgrade to the fixed software versions as indicated in the respective security advisories to remediate these vulnerabilities.
Affected and fixed releases
Temporary risk reduction
Cisco's advisory states that no workarounds are available for these vulnerabilities. Customers should apply the recommended software upgrades.
Evidence and validation checklist
- Cisco PSIRT published a combined advisory on September 2, 2026 listing CVEs and severity ratings.
- Cisco recommends upgrading to fixed software for remediation.
- No workarounds are available as per the advisory.
- Details and links to advisories and upgrade instructions are included in the source.
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
