CVE-2026-20276
Cisco IOS XR Software Security Hardening Release: September 2026
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691.
Weakness: CWE-691
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco IOS XR Software | Routing & Switching | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco IOS XR Software
Vendor advisory
cisco-sa-hardening-iosxr-qg64NcM
Cisco IOS XR Software Security Hardening Release: September 2026
Cisco’s rating: Critical (advisory CVSS 9.8) · Published Sep 2, 2026 · updated Sep 17, 2026 (revision 2.2)
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from