Cisco IOS XR Software Security Hardening Release: September 2026

Plan PatchCVSS 9.8cisco-sa-hardening-iosxr-qg64NcMSep 2, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Cisco IOS XR Software contains multiple internally discovered vulnerabilities grouped by Common Weakness Enumeration (CWE) classes. These vulnerabilities affect versions 2.0.0 through 7.9.21 of Cisco IOS XR Software and the Base product. The vulnerabilities have been addressed through software hardening releases, though no specific technical details about individual weaknesses are disclosed. Cisco states these are not known to be actively exploited. No workarounds are available.

What this means
What could happen
An attacker with network access to an IOS XR device could exploit these vulnerabilities to gain unauthorized access, execute code, or cause the device to become unavailable, potentially disrupting routing and network operations across your infrastructure.
Who's at risk
Network operators running Cisco IOS XR Software on routers and edge devices. This affects organizations with Cisco ASR, CRS, and NCS series routing platforms that use IOS XR as their operating system.
How it could be exploited
An attacker on the network reaches the IOS XR device remotely without authentication and exploits one of the multiple CWE-class vulnerabilities in the affected software versions to achieve remote code execution or privilege escalation.
Prerequisites
  • Network-reachable IOS XR device
  • Device running vulnerable IOS XR Software version 2.0.0 through 7.9.21
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Cisco IOS XR Software Security Hardening Release: September 20262.0.0 through 7.9.21Fix available
BaseAll versionsFix available
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict network access to management interfaces and control plane of IOS XR devices using firewall rules or access control lists
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Cisco IOS XR Software to a version later than 7.9.21 on all affected devices
Long-term hardening
0/1
HARDENINGSegment IOS XR devices on a separate management network with limited external connectivity
API: /api/v1/advisories/40f828d1-e650-4259-9063-8360759668d5

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.