Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-20274: Cisco IOS XR may let attackers exhaust system resources
CVE-2026-20274 · published 1 day ago
Summary
The Cisco IOS XR operating system used in many network routers has been updated to fix several internal weaknesses that could let a malicious user consume the device’s memory or processing power. If exploited, this could slow down or stop the router, affecting network performance. Apply the latest Cisco IOS XR software release as soon as possible to protect your network.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | cisco ios xr software | 6.5.29 |
Original advisory text
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resul...
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.
The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-664Improper Control of a Resource Through its Lifetime
Timeline
Published2 Sep 2026
Updated3 Sep 2026
First seen2 Sep 2026
Monitor software like this
Free during beta