Cisco Patches Eight Flaws in Network Software Used by Telecoms Worldwide, Two Rated Near-Maximum Severity

Cisco's own engineers found the vulnerabilities using artificial intelligence tools. No fixes exist beyond the patches, and two of the flaws score 9.8 out of 10 on the standard severity scale.

ThreatVectr Newsdesk· 4 min read
Photoreal, news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Cisco disclosed eight vulnerabilities in its IOS XR network operating system, two of which carry a severity score of 9.8 out of 10, on 14 July 2025.
  • The two highest-rated flaws, CVE-2026-20274 and CVE-2026-20279, could allow a remote attacker to take full control of an affected router without a password or any help from a user.
  • Every version of IOS XR, including the current IOS XR7 release, is affected regardless of how the device is configured.
  • Cisco says its internal team found the bugs using frontier AI tools and is not aware of any real-world exploitation so far.
  • Telecom companies and businesses that rely on managed network providers should ask their suppliers directly whether they have applied the patches.

Cisco, the American company that makes the networking equipment carrying much of the world's internet traffic, has released patches for eight security flaws in IOS XR, the software that runs on its high-end routers. These are the machines that sit at the core of telecom networks and large corporate infrastructure, quietly directing data from one place to another around the clock.

Two of the eight flaws are rated 9.8 out of 10 on the Common Vulnerability Scoring System (CVSS), the industry's standard scale for measuring how dangerous a software flaw is. A score of 9.8 means an attacker could exploit the bug remotely, over the internet, without knowing any passwords and without tricking a user into clicking anything.

What could an attacker actually do?

An attacker who successfully used either of the two critical flaws could gain what is called "root access," meaning complete administrative control over the router, the same level of control the router's own operators have. From there, the attacker could redirect internet traffic, change routing rules, intercept data passing through, or quietly stay hidden inside the device as a base for further attacks.

The other six flaws score between 8.2 and 8.8, still classed as "high severity." They involve incorrect memory handling, which can cause a device to crash (known as a denial-of-service attack, where a service simply stops working), and control-flow weaknesses that could, in the worst case, also lead to an attacker running their own code on the device.

David Shipley of Beauceron Security told CSO Online that full remote control of a core router and the two 9.8-rated flaws both appear in the known playbook of Salt Typhoon, a hacking group linked to Chinese state intelligence that targeted Western telecoms last year. He called the worst-case outcome "widespread network disruption and outages."

Who is at risk and what should they do?

Every organisation running any version of Cisco IOS XR is affected. Cisco has released targeted software patches, called Software Maintenance Upgrades (SMUs), which can be applied without a full system reinstall. SMUs are available for software versions from 7.3 onwards. Full fixed releases, versions 26.2.2 and 26.3.1, are coming but are not yet available.

Detail Information
Flaws disclosed 8 total
Critical (CVSS 9.8) 2: CVE-2026-20274, CVE-2026-20279
High severity (CVSS 8.2 to 8.8) 6
Affected software All IOS XR versions including IOS XR7
Patch type available now SMUs from version 7.3 onwards
First full fixed releases 26.2.2 and 26.3.1 (upcoming)

Cisco says network operators can check whether a device runs IOS XR by typing the command "show version" into the device's management console. Internet-facing routers and core routing systems should be patched first.

Erik Avakian, a technical counsellor at research firm Info-Tech Research Group, advised organisations to also review who has administrative access to these devices and to restrict it tightly. He called this a "zero-trust" approach: only the people and systems that genuinely need access to a device should be able to reach it.

For businesses that do not run their own routers but rely on a telecom company or a managed service provider, the risk is still real. If your provider's equipment is vulnerable and unpatched, your traffic could be affected. Avakian's advice is direct: ask your suppliers whether they are affected, whether they have patched, and when they expect to finish.

Cisco confirmed no exploitation has been detected so far. That window will not stay open indefinitely.

© 2026 Threat Vectr