Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-682.
Published: 2026-09-02
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from internal, incorrect calculation logic in Cisco IOS XR Software. The flaw, classified under CWE-682, can produce unintended results during packet processing or configuration handling, leading to system instability or failures. The resulting miscalculation could cause denial of service if errors propagate to critical routing decisions. No explicit exploitation path is detailed, but the possibility exists.

Affected Systems

Affected products are Cisco IOS XR Software. The advisory indicates that all versions prior to the hardening release are impacted; no specific build or release numbers are listed, and the hardening release resolves the calculation issues.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that no publicly reported exploitation has been documented. Based on the description, the likely attack vector could involve malformed traffic or configuration input that triggers the incorrect calculation, but explicit details are lacking. Considering the severity and potential system disruption, the risk is significant.

Generated by OpenCVE AI on September 3, 2026 at 09:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the Cisco IOS XR Software hardening release that resolves calculation issues
  • Check release notes to confirm the fix for the identified calculation flaw
  • Monitor network and router performance for signs of instability or denial of service after applying the update

Generated by OpenCVE AI on September 3, 2026 at 09:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco ios Xr Software
Vendors & Products Cisco
Cisco ios Xr Software

Thu, 03 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-682.
Title Cisco IOS XR Software Security Hardening Release: September 2026
Weaknesses CWE-682
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Ios Xr Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-03T03:56:31.780Z

Reserved: 2025-10-08T11:59:15.403Z

Link: CVE-2026-20275

cve-icon Vulnrichment

Updated: 2026-09-02T17:56:46.681Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T17:17:32.790

Modified: 2026-09-03T13:04:39.407

Link: CVE-2026-20275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses