CVE-2026-20278
published 2026-09-02CVE-2026-20278: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.28%
20.6th percentile
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20278 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707.
Affected
111 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco IOS XR Software up to 26.2.101 neutralization (EUVD-2026-70208)
vuldb·2026-09-02·CVSS 8.8
CVE-2026-20278 [HIGH] Cisco IOS XR Software up to 26.2.101 neutralization (EUVD-2026-70208)
A vulnerability was found in Cisco IOS XR Software. It has been rated as very critical. This issue affects some unknown processing. The manipulation leads to improper neutralization.
This vulnerability is uniquely identified as CVE-2026-20278. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review.
ghsa_unreviewed·2026-09-02·CVSS 8.8
CVE-2026-20278 [HIGH] CWE-707 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20278 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707.
No detection rules found.
No public exploits indexed.
2026-09-02
Published