Cisco IOS XR hardening release (umbrella CVEs)
Security Patch Release
Summary
Hide ▲
Show ▼
Cisco released an IOS XR hardening update that covers all IOS XR releases, including XR7 (LNT), and bundles 7 umbrella CVEs. Two of the grouped flaws are rated 9.8, and Cisco says there is no workaround for any IOS XR version. Customers must upgrade to a release with SMUs and then apply those updates. Releases outside Cisco's support table require a TAC case before the fix path can be completed.
Related Happenings
Cisco Nexus 9000 NX-OS patch release for CVE-2026-20212
Security Patch Release
H score14
First: 03.09.2026 18:52
Last: 03.09.2026 18:52
Sources 1
How related:
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
About this happening:
Cisco released NX-OS patches for CVE-2026-20212, a critical flaw affecting 10 Silicon One-based Nexus 9000 switch PIDs. The bug lets an unauthenticated remote attack...
Cisco Nexus 9000 NX-OS patch release for CVE-2026-20212
Security Patch ReleaseHow related: Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
About this happening: Cisco released NX-OS patches for CVE-2026-20212, a critical flaw affecting 10 Silicon One-based Nexus 9000 switch PIDs. The bug lets an unauthenticated remote attack...
Cisco security patch release for CVE-2026-20337
Security Patch Release
H score30
First: 11.08.2026 14:03
Last: 11.08.2026 14:03
Sources 1
About this happening:
Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...
Cisco security patch release for CVE-2026-20337
Security Patch ReleaseAbout this happening: Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...
Cisco security patch release for CVE-2026-20303
Security Patch Release
H score43
First: 06.08.2026 20:13
Last: 06.08.2026 20:13
Sources 1
About this happening:
Cisco rolled out updates for Cisco Catalyst SD-WAN Software to fix five critical CVEs across affected releases, including CVE-2026-20303 and CVE-2026-20304. Th...
Cisco security patch release for CVE-2026-20303
Security Patch ReleaseAbout this happening: Cisco rolled out updates for Cisco Catalyst SD-WAN Software to fix five critical CVEs across affected releases, including CVE-2026-20303 and CVE-2026-20304. Th...
NSA/FBI/CISA router hardening advisory
Advisory/Mitigation
H score33
First: 13.07.2026 12:32
Last: 13.07.2026 12:32
Sources 1
About this happening:
NSA, FBI, CISA and 15 allied agencies issued a joint router hardening advisory after hackers targeted vulnerable and poorly configured routers in critical infrastruc...
NSA/FBI/CISA router hardening advisory
Advisory/MitigationAbout this happening: NSA, FBI, CISA and 15 allied agencies issued a joint router hardening advisory after hackers targeted vulnerable and poorly configured routers in critical infrastruc...
Cisco Unified Communications Manager security update for CVE-2026-20230
Security Patch Release
H score56
First: 04.06.2026 14:09
Last: 04.06.2026 14:09
Sources 1
About this happening:
Cisco released security updates for Cisco Unified Communications Manager (Unified CM) to fix CVE-2026-20230, a critical flaw that could let a remote attacker reach...
Cisco Unified Communications Manager security update for CVE-2026-20230
Security Patch ReleaseAbout this happening: Cisco released security updates for Cisco Unified Communications Manager (Unified CM) to fix CVE-2026-20230, a critical flaw that could let a remote attacker reach...
Timeline
-
03.09.2026 18:52 2 articles · 3h ago
Cisco releases IOS XR hardening update with umbrella CVEs
Initial DisclosureCisco released an IOS XR hardening update that bundles 7 umbrella CVEs, including 2 rated 9.8, and says there is no workaround for any IOS XR version. The guidance is to upgrade IOS XR customers, including IOS XR7 (LNT), to a release that includes software maintenance updates (SMUs), then apply those SMUs.
Show sources
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root — thehackernews.com — 03.09.2026 18:52
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root — thehackernews.com — 03.09.2026 18:52
-
03.09.2026 18:52 1 articles · 3h ago
Cisco details IOS XR SMU availability and upgrade path
Mitigation Patch UpdateCisco's September 3 follow-up says 111 IOS XR releases are affected, with 14 releases already having SMUs available, four awaiting SMUs, and 93 requiring an upgrade before a fix can be applied. Cisco also says there may be approximately 16 SMUs available for each release, that future releases 26.2.2 and 26.3.1 will be the first fixed releases needing no SMUs, and that releases outside the table require a Technical Assistance Center case.
Show sources
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root — thehackernews.com — 03.09.2026 18:52