Cisco has issued a warning to customers regarding several critical vulnerabilities across its product lines, including three rated as critical. Two of these impact the Cisco IOS XR operating system, which powers the company's carrier-grade equipment, while the third affects certain Nexus 9000 Series Switches.
The company stated that many of these flaws were discovered during a "comprehensive internal security review," suggesting an extensive search for vulnerabilities. New versions of IOS XR have been released to address these issues, and Cisco strongly recommends that customers apply these updates.
One of the IOS XR vulnerabilities, identified as CVE-2026-20274, carries a CVSS score of 9.8. This flaw encompasses multiple buffering issues, the potential for out-of-bounds writes, and the initialization of resources with insecure default settings. Another critical IOS XR vulnerability, CVE-2026-20279, also rated 9.8, is described as an improper access control problem. This includes issues such as improper certificate validation, missing authentication for critical functions, and incorrect or missing authorization. In addition to these critical flaws, Cisco also identified a trio of vulnerabilities rated 8.8, another rated 8.6, and one scored 8.2.
The third critical vulnerability, CVE-2026-20212, was discovered by Cisco's support organization. This flaw affects certain Nexus 9000 Series Switches and stems from a problematic integration with Cisco's own Silicon One networking processors. It could allow an unauthenticated, remote attacker to execute code with root privileges on affected devices.
Specifically, TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF) configuration. An attacker could connect to an affected device and send specially crafted input, which would then be executed with root privileges. Exploitation of this vulnerability could also lead to the S1HAL process crashing, potentially causing the device to reload.
Ten Nexus 9000 devices are known to be affected by CVE-2026-20212. While a software update to permanently fix this flaw is not yet available, Cisco has provided guidance and a download to help implement mitigations. The company suggests using infrastructure access control lists (iACLs) to restrict traffic to only necessary management and control plane traffic destined for the affected device. Alternatively, iACLs can be configured to explicitly deny all TCP packets destined for a locally configured IP address on ports 43210 or 43211.
Cisco has confirmed that it has not observed any active attacks exploiting these vulnerabilities. However, the company advises prompt action given the public disclosure of these issues.






