CVE-2026-20279: pre-auth remote code execution in Cisco Cisco IOS XR Software

An unauthenticated attacker with network access can execute arbitrary code on affected Cisco IOS XR Software releases. CVE-2026-20279 stems from improper access control (CWE-284) and has a CVSS 3.1 score of 9.8, indicating remote, no-privilege, no-user-interaction exploitation. Affected versions include multiple 6.x and 7.x builds such as 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.90, 6.7.1, 7.0.1, 7.0.2, 7.0.90 and 7.1.1; an attacker only needs network reachability to the vulnerable device.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00301
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high urgency: the flaw allows unauthenticated remote code execution over the network, so immediately limit device exposure and prepare to apply vendor fixes when released.

What is CVE-2026-20279?

An unauthenticated attacker with network access can execute arbitrary code on affected Cisco IOS XR Software releases. CVE-2026-20279 stems from improper access control (CWE-284) and has a CVSS 3.1 score of 9.8, indicating remote, no-privilege, no-user-interaction exploitation. Affected versions include multiple 6.x and 7.x builds such as 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.90, 6.7.1, 7.0.1, 7.0.2, 7.0.90 and 7.1.1; an attacker only needs network reachability to the vulnerable device.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Cisco Cisco IOS XR Software are affected?

BRANCHAFFECTEDFIXED
6.x6.5.29
7.x7.0.1
6.x6.5.26
6.x6.5.25
6.x6.5.28
6.x6.5.90
7.x7.1.1
7.x7.0.90
6.x6.7.1
7.x7.0.2

Is CVE-2026-20279 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-20279

  1. Isolate affected IOS XR devices from untrusted networks and restrict management-plane access to trusted IPs.
  2. Apply access control filtering and firewall rules to block unnecessary services and ports exposed to the internet.
  3. Enable detailed logging and monitor for anomalous connections or unexpected process activity on IOS XR devices.
  4. Follow Cisco's official guidance and install vendor fixes when Cisco publishes patched releases for the listed versions.

Frequently asked questions

Is CVE-2026-20279 being actively exploited?

There are no public reports of active exploitation of CVE-2026-20279 as of 2026-09-29.

Which Cisco IOS XR Software versions are affected by CVE-2026-20279?

Multiple 6.x and 7.x builds are listed as affected, including 6.5.25, 6.5.26, 6.5.28, 6.5.29, 6.5.90, 6.7.1, 7.0.1, 7.0.2, 7.0.90 and 7.1.1.

Is there a patch for CVE-2026-20279?

As of 2026-09-29 no fixed releases are listed; follow Cisco advisories for patch availability and apply vendor fixes when provided.

Does CVE-2026-20279 require authentication?

No; the vulnerability allows unauthenticated (pre-auth) remote code execution given network access to the vulnerable Cisco IOS XR device.

References