Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch
Summary
Cisco released patches for over six vulnerabilities in its IOS XR network operating system, including two critical flaws (CVSS score, a 0-10 rating of how severe a vulnerability is, of 9.8) that could allow attackers to perform remote code execution (RCE, where an attacker can run commands on a system they don't own) and gain root access on routers to intercept traffic. The vulnerabilities affect all IOS XR versions regardless of configuration, though they are not currently known to be actively exploited in the wild.
Solution / Mitigation
Customers should use the 'show version' command to identify if their device runs Cisco IOS XR, then upgrade to a release with available software maintenance upgrades (SMUs, targeted software patches that don't require a full system upgrade) and apply appropriate SMUs. Available SMUs cover software trains starting with version 7.3, with up to 16 SMUs per release. Future Cisco IOS XR Software releases (26.2.2 and 26.3.1) will be the first fixed releases not requiring SMUs. Customers needing patches for other releases should contact their security support organization or open a Cisco service request.
Classification
Original source: https://www.csoonline.com/article/4219968/cisco-bundles-fixes-for-multiple-vulnerabilities-some-critical-into-one-patch-2.html
First tracked: September 9, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 95%