Skip to content

Leadership1 publisher2 min readPublished

Cisco patches multiple IOS XR flaws, including critical bugs, via targeted SMUs

Two of the seven flaws score 9.8, but the operational weight sits in the remediation path, which asks operators to upgrade a device first and then apply as many as 16 targeted patches. No clean fixed release exists yet.

The Board Room · Leadership desk

Illustration accompanying Cisco patches multiple IOS XR flaws, including critical bugs, via targeted SMUs

What happened

  • Cisco's own software engineering team flagged multiple internally-discovered vulnerabilities in IOS XR during regular testing, and the company bundled more than half a dozen fixes into one release.
  • Two of the seven flaws, CVE-2026-20274 and CVE-2026-20279, are rated 9.8 on CVSS and cover lifetime resource control issues, while the other five sit between 8.8 and 8.2.
  • Cisco says every IOS XR release including IOS XR7 is affected regardless of configuration, that there are no known workarounds, and that software updates are available.
  • The flaws reach remote code execution and root access on a router, which would let an attacker intercept traffic, alongside access control failures and buffer overflows.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • cost An affected device has to be moved to a patchable release before it can take the patch, so the price of this bundle is scheduled downtime on routing gear that falls to network operations rather than to the team that read the advisory.
  • constraint With no workaround to buy time, the only levers before patching are the ones Avakian lists, restricted administrative access and validated segmentation and ACLs, which draw on a different budget and a different team than a patch cycle does.
  • exposure Carriers are the named audience, because Shipley argues nation-state teams are watching this class of equipment and the worst case on the high-severity bugs is widespread outages rather than a single compromised box.
  • contradiction Cisco confirms some of the seven flaws reach code execution but has not said this holds for all seven, so severity triage inside the bundle falls to the operator rather than the vendor, and that is exactly where a rollout order gets argued.

Up to 17 discrete change actions can sit behind a single release train: the base upgrade Cisco requires first, plus as many as 16 software maintenance upgrades applied on top [13][16]. SMUs are the concession to operators, targeted patches that do not require a full system upgrade [12], but the sequencing is not optional and the available SMUs only cover software trains from version 7.3 onward [13]. For anyone running several trains across a backbone, that ceiling multiplies by the number of trains, which turns remediation largely into a scheduling exercise.

Cisco names 26.2.2 and 26.3.1 as the first fixed releases that will not require SMUs [15]; neither release exists yet [20]. CSO Online's account of the advisory carries no date for either one [21]. Waiting is therefore an open-ended position on equipment for which Cisco reports no workarounds [4], while the SMU route spends effort now that a later clean upgrade partly retires. Operators are choosing between spending that effort now on a fix that a later upgrade will partly replace, or waiting on an interval nobody can size.

The case for a measured rollout rests on provenance and on the absence of observed attacks [2][5]. Publishing the advisory, though, changes who knows about the flaws. David Shipley of Beauceron Security reads the two 9.8s as access-and-persistence bugs and places both root router access and remote code execution in the Salt Typhoon playbook [10]. Erik Avakian of Info-Tech Research Group supplies the part that should set the pace, saying the most serious of these can potentially be exploited remotely at low attack complexity, with no privileges and no user interaction [8].

Avakian puts internet-facing and core routing systems at the front of the queue, ordered by exposure and criticality [17]. The decision this quarter is which routers get the first windows. The constraint next quarter is inventory, because customers needing patches for releases Cisco has not identified are told to contact their security support organisation or open a service request [14], and a "show version" sweep [19] is what tells an operator whether remediation is a schedule or a negotiation.

What to watch

  • Whether Cisco dates 26.2.2 and 26.3.1, which decides if waiting is a schedule or an open interval.
  • Any first report of exploitation in the wild, which would collapse a prioritised rollout into an emergency one.
  • Whether carriers running trains older than version 7.3 find SMUs available or end up filing service requests.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories