{"slug": "cisco-flags-networking-os-bugs-aplenty", "title": "Cisco flags networking OS bugs aplenty", "summary": "Cisco disclosed seven vulnerabilities, CVE-2026-20274 through CVE-2026-20280, affecting its IOS XR networking operating system, with two rated critical, and a separate bug, CVE-2026-20212, in its Nexus 9000 data center switch that could allow an unauthenticated remote attacker to execute code with root privileges. The bugs were found during an internal security review, and Cisco advises upgrading to fixed releases.", "body_md": "Cisco disclosed various bugs affecting its networking operating system and switches.\n\nLabelled as CVE-2026-20274 through CVE-2026-20280, the seven vulnerabilities impact Cisco IOS XR, with two of them marked at critical severity.\n\nThe highest in severity are CVE-2026-20274 and CVE-2026-20279, with the former giving improper control of a resource through its lifetime via buffering issues, and the latter doing so via incorrect certificate validation and missing authentication for critical functions.\n\nInterestingly, Cisco's notice said the bugs were found after a comprehensive internal security review. The firm recently released via Hugging Face its [Antares AI model family](https://www.sdxcentral.com/news/cisco-security-ai-aces-openai-but-anthropic-thats-a-mythos-mystery/), purposely designed to discover vulnerabilities in a manner similar to Anthropic's Mythos model.\n\n[Alongside the IOS XR notice, Cisco flagged](https://www.sdxcentral.com/news/cisco-security-ai-aces-openai-but-anthropic-thats-a-mythos-mystery/) a separate bug – CVE-2026-20212 – affecting Silicon One integration in its [Nexus 9000 data center switch](https://www.sdxcentral.com/news/next-gen-switches-servers-everything-unveiled-at-cisco-live-emea-2026/). Cisco warned of the possibility of an unauthenticated, remote attacker being able to execute code with root privileges due to TCP ports 43210 and 43211 being exposed in the default Layer 3 (L3) virtual routing and forwarding (VRF).\n\n“The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco’s advisory warned.\n\nThe networking giant advised users to upgrade the affected Nexus 9000 switch to a fixed Cisco NX-OS release.", "url": "https://wpnews.pro/news/cisco-flags-networking-os-bugs-aplenty", "canonical_source": "https://www.sdxcentral.com/news/cisco-flags-networking-os-bugs-aplenty/", "published_at": "2026-09-07 11:28:32+00:00", "updated_at": "2026-09-07 11:56:12.328340+00:00", "lang": "en", "topics": ["ai-research"], "entities": ["Cisco", "IOS XR", "Nexus 9000", "CVE-2026-20274", "CVE-2026-20279", "CVE-2026-20212", "Hugging Face", "Anthropic"], "alternates": {"html": "https://wpnews.pro/news/cisco-flags-networking-os-bugs-aplenty", "markdown": "https://wpnews.pro/news/cisco-flags-networking-os-bugs-aplenty.md", "text": "https://wpnews.pro/news/cisco-flags-networking-os-bugs-aplenty.txt", "jsonld": "https://wpnews.pro/news/cisco-flags-networking-os-bugs-aplenty.jsonld"}}