Impact
Cisco performed an internal security review that uncovered insufficient control flow management issues classified under CWE-691. The weakness can allow an attacker to manipulate the path of execution within the IOS XR software, potentially enabling the execution of arbitrary code or other unauthorized actions. The CVSS score of 8.6 indicates a high severity impact on confidentiality, integrity, and availability if successfully exploited.
Affected Systems
Cisco IOS XR Software in all versions that have not yet incorporated the September 2026 hardening release are affected. The advisory does not list specific firmware revisions, but any device running an unpatched IOS XR image is considered vulnerable.
Risk and Exploitability
The vulnerability is high-risk with a CVSS of 8.6, but no EPSS data is available, and the issue is not listed in the CISA KEV catalog. The likely attack vector involves an attacker having network access to the device or a path to local or remote execution of privileged commands. Exploitation would require triggering the control flow bug, which typically needs a crafted packet or configuration change. Because the flaw is internal to the software’s control flow handling, local privilege escalation or full code execution is possible if the attacker can influence the control path.
OpenCVE Enrichment