Cisco IOS XR Software Security Hardening Release: September 2026
Plan PatchCVSS 9.8cisco-sa-hardening-iosxr-qg64NcMSep 2, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Cisco IOS XR Software contains multiple internally discovered vulnerabilities grouped by Common Weakness Enumeration (CWE) classes. These vulnerabilities affect versions 2.0.0 through 7.9.21 of Cisco IOS XR Software and the Base product. The vulnerabilities have been addressed through software hardening releases, though no specific technical details about individual weaknesses are disclosed. Cisco states these are not known to be actively exploited. No workarounds are available.
What this means
What could happen
An attacker with network access to an IOS XR device could exploit these vulnerabilities to gain unauthorized access, execute code, or cause the device to become unavailable, potentially disrupting routing and network operations across your infrastructure.
Who's at risk
Network operators running Cisco IOS XR Software on routers and edge devices. This affects organizations with Cisco ASR, CRS, and NCS series routing platforms that use IOS XR as their operating system.
How it could be exploited
An attacker on the network reaches the IOS XR device remotely without authentication and exploits one of the multiple CWE-class vulnerabilities in the affected software versions to achieve remote code execution or privilege escalation.
Prerequisites
- Network-reachable IOS XR device
- Device running vulnerable IOS XR Software version 2.0.0 through 7.9.21
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Cisco IOS XR Software Security Hardening Release: September 20262.0.0 through 7.9.21Fix available
BaseAll versionsFix available
Remediation & Mitigation
0/3
Do now
0/1HARDENINGRestrict network access to management interfaces and control plane of IOS XR devices using firewall rules or access control lists
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Cisco IOS XR Software to a version later than 7.9.21 on all affected devices
Long-term hardening
0/1HARDENINGSegment IOS XR devices on a separate management network with limited external connectivity
CVEs (7)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/40f828d1-e650-4259-9063-8360759668d5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.