CVE-2026-20279
Cisco IOS XR Software Security Hardening Release: September 2026
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and Moreen·The Hacker News·
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Rooten·The Hacker News· Patch Cisco Nexus 9000 rce
- Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilitiesen-us·SecurityWeek· Patch Cisco Secure Email rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20279 and every CVE in our database. Create a free account — no credit card required.
Create Free Account