AI description
CVE-2026-20279 identifies a set of improper access control vulnerabilities within Cisco IOS XR Software, categorized under Common Weakness Enumeration (CWE) CWE-284. These issues were discovered internally by Cisco's engineering team during a comprehensive security review. The vulnerabilities encompassed by CVE-2026-20279 include missing authentication for critical functions, improper certificate validation, and incorrect authorization. Exploitation of these flaws could allow a remote attacker to bypass existing authentication or authorization mechanisms, thereby gaining unauthorized access to critical functionalities or protected resources.
- Description
- As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
- Source
- psirt@cisco.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@cisco.com
- CWE-284
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
35
🚨 Upozorňujeme na kritické zranitelnosti v Cisco Nexus 9000 Series Switches a Cisco IOS XR Software, CVE-2026-20212, CVE-2026-20274 a CVE-2026-20279. Zranitelnost CVE-2026-20212 umožňuje neautentizovanému vzdálenému útočníkovi spustit libovolný kód s oprávnění
@GOVCERT_CZ
4 Sept 2026
418 Impressions
1 Retweet
7 Likes
1 Bookmark
0 Replies
0 Quotes
【また君か】Cisco IOS XRに複数の重大(Critical)な脆弱性。CVE-2026-20274はCVSSスコア9.8で、詳細非開示の境界外書き込み。CVE-2026-20279もCVSSスコア9.8で、不適切なアクセス制御。その他脆弱性も修正あり。 https://t.co/hVti
@__kokumoto
4 Sept 2026
56906 Impressions
25 Retweets
74 Likes
21 Bookmarks
0 Replies
3 Quotes
Cisco released security updates for IOS XR addressing multiple vulnerabilities discovered internally. CVE-2026-20274 and CVE-2026-20279 score 9.8 CVSS due to resource management and access control flaws. Three additional issues score 8.8, with others at 8.6 and 8.2. No
@WorldCyberNewsX
3 Sept 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The severity is increased for this new vulnerability affecting Cisco IOS XR Software (CVE-2026-20279) https://t.co/ZhI6hJFSp1
@vuldb
3 Sept 2026
118 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes