[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-cisco-patches-eight-flaws-spanning-ios-xr-and-nexus-9000":10,"sections":49},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":38,"tags":39,"sources":44,"feedback":48,"feedback_at":22,"cost_usd":48,"total_tokens":48},6080,"cisco-patches-eight-flaws-spanning-ios-xr-and-nexus-9000","Cisco Patches Eight Flaws Spanning IOS XR and Nexus 9000","Cisco patched eight vulnerabilities across two advisories covering IOS XR software and Nexus 9000 switches, three of them critical.","Cisco patched eight vulnerabilities in IOS XR and Nexus 9000 switches, three of them critical enough to let attackers in without logging in at all.\n\nThe company published two advisories on September 2. One covers seven flaws in IOS XR software, including two critical bugs, CVE-2026-20274 and CVE-2026-20279, both rated 9.8 out of 10. One is a resource-handling flaw, the other an access-control failure, and either lets an attacker reach a device over the network with no authentication and no user interaction. Those seven bugs affect every release of IOS XR, including IOS XR7 (LNT), and there is no workaround, so patching is the only fix. The second advisory covers a separate critical bug, CVE-2026-20212, which hits Nexus 9000 Series switches running Cisco's Silicon One ASIC; exploiting it lets an attacker execute code without root privileges and can crash the switch's S1HAL process, forcing a reload. Cisco offers an iACL workaround for that one, restricting traffic on ports 43210 and 43211.\n\nCisco says none of these bugs has been exploited yet, but \"critical, unauthenticated, reachable over the network\" is exactly the combination that gets weaponized fast once patches are public. IOS XR runs core routers that ISPs and large enterprises depend on, so a missed patch here is a backbone problem, not a laptop problem.\n\nCisco calls this the result of a \"comprehensive internal security review,\" which is a polite way of saying it went looking and found a lot. Given how often IOS XR turns up in Cisco's advisories, this probably isn't the last batch this year.","[\"cisco\",\"ios-xr\",\"nexus-9000\",\"vulnerabilities\"]","2026-09-04T13:55:00.000Z","2026-09-04T15:08:43.338Z","2026-09-04T15:08:55.270Z","published",null,[24,30,34],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Fix the dek: it claims all three flaws let attackers 'take over IOS XR devices without a password,' but the body only supports no-login\u002Funauthenticated exploitation for the two 9.8-rated CVEs — the third (CVE-2026-20212) is described as a crafted-input code-execution\u002Fcrash bug on Nexus 9000 switches with no stated authentication bypass, so the dek should scope the 'without a password, take over' claim to just the two critical CVEs.","resolved",{"id":31,"reviewer":26,"round":32,"reason":33,"status":29},"editor-r2",2,"Fix the headline: it labels all three flaws 'IOS XR Flaws,' but the third (CVE-2026-20212) affects Nexus 9000 switches with a Silicon One ASIC, not IOS XR software — retitle to reflect that only two of the three critical bugs are IOS XR flaws.",{"id":35,"reviewer":26,"round":36,"reason":37,"status":29},"editor-r3",3,"The headline now correctly splits two IOS XR bugs from one Nexus flaw, but the dek still calls all eight patched vulnerabilities 'IOS XR flaws' while also saying the Nexus bug 'hits... not the router software itself' — fix the dek to say Cisco patched eight vulnerabilities across IOS XR and Nexus 9000 advisories, not eight IOS XR flaws.","security",[40,41,42,43],"cisco","ios-xr","nexus-9000","vulnerabilities",[45],{"name":46,"url":47},"TechRadar","https:\u002F\u002Fwww.techradar.com\u002Fpro\u002Fsecurity\u002Fcisco-patches-three-critical-vulnerabilities-as-part-of-comprehensive-internal-security-review",0,{"sections":50},[51,56,60,65,70,75,80,85,90,95,100,105,110,115],{"name":52,"slug":53,"count":54,"latest_published_at":55},"AI","ai",3385,"2026-09-04T22:17:36.000Z",{"name":57,"slug":38,"count":58,"latest_published_at":59},"Security",565,"2026-09-05T00:03:08.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Policy","policy",300,"2026-09-04T22:18:34.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Hardware","hardware",152,"2026-09-03T09:26:48.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Consumer Tech","consumer-tech",97,"2026-09-04T15:29:18.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Science","science",96,"2026-09-03T22:30:00.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Startups","startups",54,"2026-09-04T23:36:14.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":106,"slug":107,"count":108,"latest_published_at":109},"General","general",37,"2026-09-04T20:22:41.000Z",{"name":111,"slug":112,"count":113,"latest_published_at":114},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":116,"slug":117,"count":118,"latest_published_at":119},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]