Cisco Patches Critical IOS XR and Nexus 9000 Vulnerabilities

Cisco's September 2026 security review found critical flaws in IOS XR and Nexus 9000 gear, weeks after a firewall zero-day was exploited.

Sep 6, 2026 - 07:08
4 min read
 0
Cisco Patches Critical IOS XR and Nexus 9000 Vulnerabilities

Cisco spent most of August scrambling to fix a firewall bug that attackers were already using to knock corporate VPNs offline. Then, on September 2, the company's own internal security review turned up a fresh batch of critical holes — this time in the software that runs core routers and data-center switches at some of the world's largest networks.

What the internal review found

Cisco's Product Security Incident Response Team (PSIRT) disclosed seven vulnerabilities in IOS XR, the operating system that powers its carrier-grade routers, two of which are rated critical: CVE-2026-20274 and CVE-2026-20279. Cisco says both affect every current release of IOS XR regardless of how the device is configured, and there's no workaround — the only fix is to install the patch. Separately, CVE-2026-20212 hits Nexus 9000 switches built with a Silicon One chip, letting an attacker who can already reach the device send it crafted data that runs as if it had root access — the highest level of control over a machine, meaning the attacker isn't just peeking at traffic, they can effectively take the switch over.

None of these three were reported by outside researchers or found being exploited. Cisco says they turned up during the "comprehensive internal security review" the company kicked off after a rougher few months of firewall bugs — which is either reassuring (they're finding their own problems) or a little unsettling, depending on how much you trust that this was the last of them.

The bug that started the review

That review exists because of CVE-2026-20349, a flaw in Cisco's ASA and FTD firewall software that attackers were already exploiting in the wild back in August. Sending one crafted request to a device's remote-access SSL VPN service — the same kind of VPN connection employees use to reach office networks from home — could force it to crash and reboot, cutting off every VPN session running through it. It scored 8.6 out of 10 on the industry's severity scale, and the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch by August 14.

A zero-day already being used against real networks, followed weeks later by three more critical bugs found in Cisco's own back yard — that's not a great month for anyone running Cisco gear.

Why Indian networks should pay attention

Cisco routers and switches sit underneath a big chunk of India's telecom backbone, banking networks, and enterprise data centers — the same category of edge firewall and VPN gear that CVE-2026-20349 targeted is standard equipment for Indian ISPs, NBFCs, and IT service exporters who route client traffic through remote-access VPNs. CERT-In, the government's cyber emergency response team, has flagged multiple Cisco advisories through 2026 already, and unpatched carrier-grade routers are exactly the kind of infrastructure that shows up in RBI and SEBI cybersecurity audits after the fact, not before. For an Indian bank or a BPO handling international traffic, a Nexus 9000 switch running as root under someone else's control isn't a hypothetical — it's the sort of incident that ends up in a regulatory disclosure.

What to actually do about it

Cisco's advisories come with fixed software releases, and security teams have a short list of priorities this week:

  • Patch internet-facing ASA and FTD devices for CVE-2026-20349 first — it's the one already being exploited.
  • Check whether any IOS XR routers are exposed to untrusted networks and apply the September 2 patches even if the device "looks fine."
  • Inventory Nexus 9000 switches for the Silicon One ASIC and prioritize those reachable from less-trusted parts of the network.
  • Don't wait for a scanner to flag it — Cisco says there's no workaround for the IOS XR bugs beyond patching.

None of this is exotic — it's routine patch management. But routine is exactly what slips when a security team is juggling four Cisco advisories in six weeks. The bigger story here isn't any single CVE; it's that the equipment sitting quietly at the center of a network is rarely anyone's first worry until it's the reason for one.

Short URL: https://code24.in/5bbad090

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Code24 Team Code24 Team