Forwarded from Taiwan Computer Emergency Response Coordination Center Cybersecurity Information Alert TWCERTCC-200-202609-00000004
[Content Description]
The Cisco IOS XR Software development team discovered multiple security vulnerabilities during an internal security review and has completed the fixes. There is currently no evidence that these vulnerabilities have been actively exploited. To help customers deploy security updates in a timely manner and simplify the vulnerability disclosure process, Cisco has publicly disclosed the relevant vulnerability information and remediation recommendations.
CVE-2026-20280(CVSS:8.8), is an improper check or handling of exceptional conditions.
CVE-2026-20279(CVSS:9.8), is an improper access control vulnerability.
CVE-2026-20278(CVSS:8.8), is an improper handling vulnerability.
CVE-2026-20275(CVSS:8.8), is an incorrect calculation, including incorrect calculation of buffer sizes, integer overflow, etc.
CVE-2026-20274(CVSS:9.8), is improper control of a resource throughout its lifecycle.
[Affected Platforms]
For the detailed list of affected products and versions, please refer to the official website announcement.
[Recommended Measures]
Please apply the fixes according to the solutions released on the official website.
[References]
1. https://www.twcert.org.tw/tw/cp-169-11186-faaa9-1.html