Cisco IOS XR Software vulnerability

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20278 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707.

Published 2 Sep 2026Updated 15 Sep 20262 sources
CVSS 8.8

What happened

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20278 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707.

Affected versions

Cisco IOS XR Software: 6.5.29; 7.0.1; 6.5.26; 6.5.25; 6.5.28; 6.5.90; 7.1.1; 7.0.90; 6.7.1; 7.0.2; 7.1.15; 7.2.1; 7.1.2; 6.7.2; 7.0.11; 7.0.12; 7.0.14; 7.1.25; 7.2.12; 7.3.1; 7.1.3; 6.7.3; 7.4.1; 7.2.2; 6.7.4; 6.5.31; 7.3.15; 7.3.16; 6.8.1; 7.4.15; 6.5.32; 7.3.2; 7.5.1; 7.4.16; 7.3.27; 7.6.1; 7.5.2; 7.8.1; 7.6.15; 7.5.12; 7.8.12; 7.3.3; 7.7.1; 6.8.2; 7.3.4; 7.4.2; 6.7.35; 6.9.1; 7.6.2; 7.5.3; 7.7.2; 6.9.2; 7.9.1; 7.10.1; 7.8.2; 7.5.4; 6.5.33; 7.8.22; 7.7.21; 7.9.2; 7.3.5; 7.5.5; 7.11.1; 7.9.21; 7.10.2; 24.1.1; 7.6.3; 7.3.6; 7.5.52; 7.11.2; 24.2.1; 24.1.2; 24.2.11; 24.3.1; 24.4.1; 24.2.2; 7.8.23; 7.11.21; 24.2.20; 24.3.2; 24.4.10; 6.5.35; 25.1.1; 24.4.2; 24.3.20; 24.4.15; 25.2.1; 6.5.351; 25.1.2; 24.3.30; 25.3.1; 6.5.352; 24.4.30; 24.2.21; 25.4.1; 25.2.2; 25.2.15; 7.2.0; 7.0.0; 25.2.30; 6.5.353; 26.1.1; 25.1.30; 25.3.15; 26.2.100; 25.4.2; 26.2.1; 25.4.30; 26.1.2; 25.4.201; 26.2.101 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.