Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

Cisco IOS XR Software: Unauthenticated Adjacent Attack Allows Denial of Service

CVE-2026-20074
Summary

Cisco IOS XR software has a vulnerability that allows an attacker on the same network to cause the routing system to crash, temporarily disrupting connectivity to connected networks. This can be exploited by sending specially crafted messages to the system. To protect against this, ensure that your systems are up to date with the latest security patches.

Original title
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-I...
Original description
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly.

This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacker could exploit this vulnerability by sending crafted IS-IS packets to an affected device after forming an adjacency. A successful exploit could allow the attacker to cause the IS-IS process to restart unexpectedly, resulting in a temporary loss of connectivity to advertised networks and a denial of service (DoS) condition.
Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2-adjacent to the affected device and must have formed an adjacency.  
nvd CVSS3.1 7.4
Vulnerability type
CWE-1287
Published: 11 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026