Cisco patched eight vulnerabilities in IOS XR and Nexus 9000 switches, three of them critical enough to let attackers in without logging in at all.
The company published two advisories on September 2. One covers seven flaws in IOS XR software, including two critical bugs, CVE-2026-20274 and CVE-2026-20279, both rated 9.8 out of 10. One is a resource-handling flaw, the other an access-control failure, and either lets an attacker reach a device over the network with no authentication and no user interaction. Those seven bugs affect every release of IOS XR, including IOS XR7 (LNT), and there is no workaround, so patching is the only fix. The second advisory covers a separate critical bug, CVE-2026-20212, which hits Nexus 9000 Series switches running Cisco's Silicon One ASIC; exploiting it lets an attacker execute code without root privileges and can crash the switch's S1HAL process, forcing a reload. Cisco offers an iACL workaround for that one, restricting traffic on ports 43210 and 43211.
Cisco says none of these bugs has been exploited yet, but "critical, unauthenticated, reachable over the network" is exactly the combination that gets weaponized fast once patches are public. IOS XR runs core routers that ISPs and large enterprises depend on, so a missed patch here is a backbone problem, not a laptop problem.
Cisco calls this the result of a "comprehensive internal security review," which is a polite way of saying it went looking and found a lot. Given how often IOS XR turns up in Cisco's advisories, this probably isn't the last batch this year.