CVE-2026-20274

Published Sep 2, 2026

Last updated 15 hours ago

CVSS critical 9.8
Cisco IOS XR Software

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-20274 is a vulnerability found in Cisco IOS XR Software, categorized under Common Weakness Enumeration (CWE) CWE-664, which pertains to improper control of a resource through its lifetime. This issue was identified during a comprehensive internal security review conducted by the Cisco IOS XR Software engineering team. The vulnerability allows a remote attacker to exploit the system by sending specially crafted input. Successful exploitation could lead to the execution of arbitrary code or cause a denial of service condition on the affected device.

Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.
Source
psirt@cisco.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@cisco.com
CWE-664

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

35