Skip to main content
CiscoLaunch

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

What happened

Cisco has released new versions of its IOS XR operating system to fix multiple security vulnerabilities, including two critical-rated flaws.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

security Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company's carrier-grade kit. CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default. CVE-2026-20279 is another 9.8-rated flaw. Cisco says it's an improper access control problem that covers "improper certificate validation, missing authentication for critical function, missing authorization, and incorrect authorization." Cisco also spotted a trio of 8.8-rated flaws, plus another rated 8.6 and one more scored at 8.2 The company's advisory says the company found the flaws after "a comprehensive internal security review," language that perhaps hints at Cisco dabbling with Mythos and/or other bug-finding models. The fix is in: Cisco has published new versions of IOS XR that fix the problems and "strongly recommends" customers adopt them. Cisco's support organization spotted the third critical flaw it revealed on Wednesday. CVE-2026-20212 is a tad embarrassing because the cause is a bad integration with Cisco's own Silicon One networking processors...

Keep reading with a free account

The rest of this article, and every signal for Cisco, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Product
IOS XR

The full record

From the Signal API record

Details

Release type
Version

Topics and mentions

Product tags

  • general technology
  • security

Extraction

Confidence
90%
Detected
Sep 4, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Cisco and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Cisco this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/46999093-82fb-22a0-6052-32b5c5629476 returns this record as JSON. POST /v1/companies/enrich returns every signal for cisco.com.

{
  "signal_id": "46999093-82fb-22a0-6052-32b5c5629476",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-09-04T02:18:36+00:00",
  "company": {
    "name": "Cisco",
    "domain": "cisco.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410",
    "title": "Cisco searched for IOS XR bugs and found so many it rolled them into an update release",
    "excerpt": "security Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit. CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default. CVE-2026-20279 is another 9.8-rated flaw. Cisco says it’s an improper access control problem that covers “improper certificate validation, missing authentication for critical function, missing authorization, and incorrect authorization.” Cisco also spotted a trio of 8.8-rated flaws, plus another rated 8.6 and one more scored at 8.2 The company’s advisory says the company found the flaws after “a comprehensive internal security review,” language that perhaps hints at Cisco dabbling with Mythos and/or other bug-finding models. The fix is in: Cisco has published new versions of IOS XR that fix the problems and “strongly recommends” customers adopt them. Cisco’s support organization spotted the third critical flaw it revealed on Wednesday. CVE-2026-20212 is a tad embarrassing because the cause is a bad integration with Cisco’s own Silicon One networking processors that...",
    "product": "IOS XR",
    "summary": "Cisco has released new versions of its IOS XR operating system to fix multiple security vulnerabilities, including two critical-rated flaws.",
    "planning": false,
    "image_url": "https://image.theregister.com/5294415.jpg?imageId=5294415&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 0.9,
    "product_data": {
      "name": "IOS XR",
      "full_text": "new versions of IOS XR",
      "fuzzy_match": false,
      "release_type": "version"
    },
    "product_tags": [
      "general_technology",
      "security"
    ],
    "published_at": "2026-09-04T02:18:36Z",
    "article_sentence": "Cisco has published new versions of IOS XR that fix the problems and “strongly recommends” customers adopt them."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.