Impact
The advisory identifies multiple internally discovered vulnerabilities in Cisco IOS XR Software that are classified as improper neutralization of input during the generation of web pages, as enumerated by CWE‑707. Because the advisory does not disclose the precise nature of the neutralization failure, the exact impact is not detailed, but improper neutralization generally indicates a risk of data leakage or code execution if input is not properly sanitized.
Affected Systems
All builds of Cisco IOS XR Software released before the September 2026 hardening release are vulnerable. Exact affected version numbers are not listed in the advisory, so any installation of IOS XR prior to the release should be considered impacted.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. The EPSS score is not available, making the probability of exploitation uncertain. The advisory does not provide a formal attack vector or exploit details, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment