Impact
The vulnerabilities referenced by CVE‑2026‑20277 are protection‑mechanism failures discovered during Cisco’s internal security review of IOS XR. A failure in a critical security control can allow an attacker to bypass intended safeguards, potentially leading to unauthorized access, data compromise, or denial of service. The assigned CVSS score of 8.2 indicates a severe impact on confidentiality, integrity, and availability.
Affected Systems
The affected product is Cisco IOS XR Software, but the advisory does not list specific firmware revisions or hardware platforms. All installations of Cisco IOS XR that are running any unreleased or pre‑hardening firmware may be vulnerable until the patched release is applied.
Risk and Exploitability
Because the EPSS score is unavailable and the vulnerability is not yet listed in CISA’s KEV catalog, the documented exploitation risk is unknown, but the high CVSS score suggests that if a relevant attack vector exists—such as remote configuration or management traffic—an attacker with sufficient privileges could exploit the control failure. Until the update is in place, the risk of successful exploitation remains significant.
OpenCVE Enrichment