DIRAS TAKE
Urgent: treat this as high priority because the vulnerability allows remote, unauthenticated network access and carries a CVSS 9.8 rating; act now to reduce exposure and monitor devices while Cisco publishes fixes or guidance.
What is CVE-2026-20274?
A remote attacker can exploit an improper resource control vulnerability in Cisco IOS XR Software to impact confidentiality, integrity, and availability. CVE-2026-20274 affects multiple 6.x and 7.x IOS XR builds, including reported affected builds such as 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.90, 6.7.1, 7.0.1, 7.0.2, 7.0.90 and 7.1.1. The flaw requires only network access and does not require valid privileges or user interaction, per the vulnerability data and CVSS vector (AV:N/PR:N/UI:N).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Cisco Cisco IOS XR Software are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 6.x | 6.5.29 | |
| 7.x | 7.0.1 | |
| 6.x | 6.5.26 | |
| 6.x | 6.5.25 | |
| 6.x | 6.5.28 | |
| 6.x | 6.5.90 | |
| 7.x | 7.1.1 | |
| 7.x | 7.0.90 | |
| 6.x | 6.7.1 | |
| 7.x | 7.0.2 |
Is CVE-2026-20274 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-20274
- Isolate affected IOS XR devices from untrusted networks and restrict management plane access to trusted hosts.
- Follow Cisco's product advisories and apply vendor guidance as soon as patches or mitigations are released.
- Monitor device logs and network telemetry for unusual resource consumption or signs of compromise.
- Harden access controls, enable network-level filtering, and maintain up-to-date inventories of affected builds for rapid remediation.
Frequently asked questions
Is CVE-2026-20274 being actively exploited?
There are no public reports of exploitation of CVE-2026-20274 as of 2026-09-29.
Which Cisco IOS XR Software versions are affected by CVE-2026-20274?
Cisco IOS XR Software versions in the 6.x and 7.x branches are affected; reported affected builds include 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.90, 6.7.1, 7.0.1, 7.0.2, 7.0.90 and 7.1.1.
Is there a patch for CVE-2026-20274?
As of 2026-09-29 no fixed releases are listed for the affected builds; follow Cisco advisories for patches or hardening updates.
Does CVE-2026-20274 require authentication?
No — the vulnerability can be triggered by a remote attacker over the network without authentication or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20274
- cve.org/CVERecord?id=CVE-2026-20274
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026