AI Weekly Malaysia

Back to items Summaries

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

ID
21373
Status
summarized
Published
04 Sep 2026, 10:18 AM
Fetched
04 Sep 2026, 12:27 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
3.0
Created
04 Sep 2026, 12:27 PM
Tags
Audience
developerssaas_founders

What happened

Cisco's internal security review uncovered multiple critical vulnerabilities in IOS XR, including two CVSS 9.8 flaws (CVE-2026-20274 covering buffer issues and insecure defaults, CVE-2026-20279 covering improper access control and missing authentication). A third critical flaw, CVE-2026-20212, allows unauthenticated remote root code execution on ten Nexus 9000 Series Switch models via TCP ports 43210 and 43211 due to a bad integration with Cisco's Silicon One processors. Fixes are in new IOS XR releases; the Nexus 9000 issue has no patch yet, only iACL mitigation.

Why it matters

If your infrastructure runs Cisco Nexus 9000 or IOS XR carrier-grade kit, you need to apply the new IOS XR versions and implement iACLs on ports 43210/43211 immediately. For everyone else not operating this hardware, there is no direct action required.

Discussion angle

Cisco found these bugs through an internal review—possibly using AI bug-finding models—so the angle is whether AI-assisted code auditing will surface a flood of similar critical CVEs across legacy infrastructure vendors, and what that means for patch cadence pressure on ops teams.

Top