# Cisco flags networking OS bugs aplenty

> Source: <https://www.sdxcentral.com/news/cisco-flags-networking-os-bugs-aplenty/>
> Published: 2026-09-07 11:28:32+00:00

Cisco disclosed various bugs affecting its networking operating system and switches.

Labelled as CVE-2026-20274 through CVE-2026-20280, the seven vulnerabilities impact Cisco IOS XR, with two of them marked at critical severity.

The highest in severity are CVE-2026-20274 and CVE-2026-20279, with the former giving improper control of a resource through its lifetime via buffering issues, and the latter doing so via incorrect certificate validation and missing authentication for critical functions.

Interestingly, Cisco's notice said the bugs were found after a comprehensive internal security review. The firm recently released via Hugging Face its [Antares AI model family](https://www.sdxcentral.com/news/cisco-security-ai-aces-openai-but-anthropic-thats-a-mythos-mystery/), purposely designed to discover vulnerabilities in a manner similar to Anthropic's Mythos model.

[Alongside the IOS XR notice, Cisco flagged](https://www.sdxcentral.com/news/cisco-security-ai-aces-openai-but-anthropic-thats-a-mythos-mystery/) a separate bug – CVE-2026-20212 – affecting Silicon One integration in its [Nexus 9000 data center switch](https://www.sdxcentral.com/news/next-gen-switches-servers-everything-unveiled-at-cisco-live-emea-2026/). Cisco warned of the possibility of an unauthenticated, remote attacker being able to execute code with root privileges due to TCP ports 43210 and 43211 being exposed in the default Layer 3 (L3) virtual routing and forwarding (VRF).

“The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco’s advisory warned.

The networking giant advised users to upgrade the affected Nexus 9000 switch to a fixed Cisco NX-OS release.
