Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.
Published: 2026-09-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerabilities tracked by CVE-2026-20274 are internal discoveries categorized under CWE‑664, indicating improper resource control. This flaw permits a component to consume more system resources than intended, which could exhaust memory or CPU and cause critical processes to terminate, effectively shutting down network services. The description does not specify whether elevated privileges are required, implying that a user with sufficient access could trigger the overuse.

Affected Systems

All Cisco IOS XR Software devices that have not applied the September 2026 Security Hardening Release. The affected vendor is Cisco and the product is Cisco IOS XR Software. No specific version list is given, so the advisory applies to all revisions that have not incorporated the new release.

Risk and Exploitability

The CVSS score of 9.8 classifies this vulnerability as critical, indicating that special conditions are not required and successful exploitation would cause significant damage. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, yet the high base score signals that it can be highly valuable to threat actors. Based on the description, the most likely attack vector is a remote exploitation via a privileged interface such as the command‑line or management session, but the lack of explicit guidance means that any interface capable of manipulating the affected component could be used. The potential for denial of Service makes this flaw especially dangerous to network operations.

Generated by OpenCVE AI on September 3, 2026 at 09:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Cisco IOS XR Software Security Hardening Release for September 2026 to all affected devices.
  • Configure and enforce resource quotas and limits on critical processes to prevent abnormal use.
  • Disable or restrict any unused services that could expose the vulnerable component.
  • Monitor system logs and performance metrics for signs of resource exhaustion or abnormal behavior.

Generated by OpenCVE AI on September 3, 2026 at 09:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco ios Xr Software
Vendors & Products Cisco
Cisco ios Xr Software

Thu, 03 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.
Title Cisco IOS XR Software Security Hardening Release: September 2026
Weaknesses CWE-664
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Ios Xr Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-03T03:56:33.256Z

Reserved: 2025-10-08T11:59:15.403Z

Link: CVE-2026-20274

cve-icon Vulnrichment

Updated: 2026-09-02T17:56:48.593Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T17:17:32.630

Modified: 2026-09-03T13:04:39.223

Link: CVE-2026-20274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime