DIRAS TAKE
Treat this as high urgency: the flaw allows unauthenticated remote code execution over the network, so immediately limit device exposure and prepare to apply vendor fixes when released.
What is CVE-2026-20279?
An unauthenticated attacker with network access can execute arbitrary code on affected Cisco IOS XR Software releases. CVE-2026-20279 stems from improper access control (CWE-284) and has a CVSS 3.1 score of 9.8, indicating remote, no-privilege, no-user-interaction exploitation. Affected versions include multiple 6.x and 7.x builds such as 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.90, 6.7.1, 7.0.1, 7.0.2, 7.0.90 and 7.1.1; an attacker only needs network reachability to the vulnerable device.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Cisco Cisco IOS XR Software are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 6.x | 6.5.29 | |
| 7.x | 7.0.1 | |
| 6.x | 6.5.26 | |
| 6.x | 6.5.25 | |
| 6.x | 6.5.28 | |
| 6.x | 6.5.90 | |
| 7.x | 7.1.1 | |
| 7.x | 7.0.90 | |
| 6.x | 6.7.1 | |
| 7.x | 7.0.2 |
Is CVE-2026-20279 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-20279
- Isolate affected IOS XR devices from untrusted networks and restrict management-plane access to trusted IPs.
- Apply access control filtering and firewall rules to block unnecessary services and ports exposed to the internet.
- Enable detailed logging and monitor for anomalous connections or unexpected process activity on IOS XR devices.
- Follow Cisco's official guidance and install vendor fixes when Cisco publishes patched releases for the listed versions.
Frequently asked questions
Is CVE-2026-20279 being actively exploited?
There are no public reports of active exploitation of CVE-2026-20279 as of 2026-09-29.
Which Cisco IOS XR Software versions are affected by CVE-2026-20279?
Multiple 6.x and 7.x builds are listed as affected, including 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.90, 6.7.1, 7.0.1, 7.0.2, 7.0.90 and 7.1.1.
Is there a patch for CVE-2026-20279?
As of 2026-09-29 no fixed releases are listed; follow Cisco advisories for patch availability and apply vendor fixes when provided.
Does CVE-2026-20279 require authentication?
No; the vulnerability allows unauthenticated (pre-auth) remote code execution given network access to the vulnerable Cisco IOS XR device.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20279
- cve.org/CVERecord?id=CVE-2026-20279
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026