LIVE · cybersecurity feed
Live wire
Cisco searched for IOS XR bugs and found so many it rolled them into an update releaseAttackers exploit zero-days in consistently besieged SonicWall productIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy Backdoor
vulnerabilitycritical

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

zeroday.news ·

Cisco has issued a warning to customers regarding several critical vulnerabilities across its product lines, including three rated as critical. Two of these impact the Cisco IOS XR operating system, which powers the company's carrier-grade equipment, while the third affects certain Nexus 9000 Series Switches.

The company stated that many of these flaws were discovered during a "comprehensive internal security review," suggesting an extensive search for vulnerabilities. New versions of IOS XR have been released to address these issues, and Cisco strongly recommends that customers apply these updates.

One of the IOS XR vulnerabilities, identified as CVE-2026-20274, carries a CVSS score of 9.8. This flaw encompasses multiple buffering issues, the potential for out-of-bounds writes, and the initialization of resources with insecure default settings. Another critical IOS XR vulnerability, CVE-2026-20279, also rated 9.8, is described as an improper access control problem. This includes issues such as improper certificate validation, missing authentication for critical functions, and incorrect or missing authorization. In addition to these critical flaws, Cisco also identified a trio of vulnerabilities rated 8.8, another rated 8.6, and one scored 8.2.

The third critical vulnerability, CVE-2026-20212, was discovered by Cisco's support organization. This flaw affects certain Nexus 9000 Series Switches and stems from a problematic integration with Cisco's own Silicon One networking processors. It could allow an unauthenticated, remote attacker to execute code with root privileges on affected devices.

Specifically, TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF) configuration. An attacker could connect to an affected device and send specially crafted input, which would then be executed with root privileges. Exploitation of this vulnerability could also lead to the S1HAL process crashing, potentially causing the device to reload.

Ten Nexus 9000 devices are known to be affected by CVE-2026-20212. While a software update to permanently fix this flaw is not yet available, Cisco has provided guidance and a download to help implement mitigations. The company suggests using infrastructure access control lists (iACLs) to restrict traffic to only necessary management and control plane traffic destined for the affected device. Alternatively, iACLs can be configured to explicitly deny all TCP packets destined for a locally configured IP address on ports 43210 or 43211.

Cisco has confirmed that it has not observed any active attacks exploiting these vulnerabilities. However, the company advises prompt action given the public disclosure of these issues.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Most of the bugs Claude Mythos found have never been checked by a human

Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became published security advisories, with counts current as of May 22, 2026. The other 21,119 candidates have not been reviewed by any

vulnerability

New infosec products of the week: September 4, 2026

Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because of its strategic posi

vulnerabilityhigh

Attackers exploit zero-days in consistently besieged SonicWall product

SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025. The post Attackers exploit zero-days in consistently besieged SonicWall product appeared first on CyberScoop.

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

ai

OpenAI commits $1B in AI credits to frontline cyber defenders

Daybreak program brings subsidized models, training, and support to under-resourced teams