Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-20279: Cisco IOS XR may let unauthorized users access protected features
CVE-2026-20279 · published 1 day ago
Summary
Cisco’s IOS XR operating system contains several access‑control gaps that could let someone without proper rights reach functions they shouldn’t. This could expose configuration data or allow changes that affect network stability. Apply the latest Cisco IOS XR hardening update as soon as possible to close the gaps.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | cisco ios xr software | 6.5.29 |
Original advisory text
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resul...
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
The vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-284Improper Access Control
Timeline
Published2 Sep 2026
Updated3 Sep 2026
First seen2 Sep 2026
Monitor software like this
Free during beta