Impact
The vulnerabilities tracked by CVE-2026-20274 are internal discoveries categorized under CWE‑664, indicating improper resource control. This flaw permits a component to consume more system resources than intended, which could exhaust memory or CPU and cause critical processes to terminate, effectively shutting down network services. The description does not specify whether elevated privileges are required, implying that a user with sufficient access could trigger the overuse.
Affected Systems
All Cisco IOS XR Software devices that have not applied the September 2026 Security Hardening Release. The affected vendor is Cisco and the product is Cisco IOS XR Software. No specific version list is given, so the advisory applies to all revisions that have not incorporated the new release.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as critical, indicating that special conditions are not required and successful exploitation would cause significant damage. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, yet the high base score signals that it can be highly valuable to threat actors. Based on the description, the most likely attack vector is a remote exploitation via a privileged interface such as the command‑line or management session, but the lack of explicit guidance means that any interface capable of manipulating the affected component could be used. The potential for denial of Service makes this flaw especially dangerous to network operations.
OpenCVE Enrichment