CVE-2026-20280
published 2026-09-02CVE-2026-20280: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.27%
19.0th percentile
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.
Affected
111 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
| cisco | cisco_ios_xr_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco IOS XR Software up to 26.2.101 improper check or handling of exceptional conditions (EUVD-2026-70207)
vuldb·2026-09-02·CVSS 8.8
CVE-2026-20280 [HIGH] Cisco IOS XR Software up to 26.2.101 improper check or handling of exceptional conditions (EUVD-2026-70207)
A vulnerability identified as very critical has been detected in Cisco IOS XR Software. The affected element is an unknown function. This manipulation causes improper check or handling of exceptional conditions.
The identification of this vulnerability is CVE-2026-20280. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review.
ghsa_unreviewed·2026-09-02·CVSS 8.8
CVE-2026-20280 [HIGH] CWE-703 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
Hackernews
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
blogs_hackernews·2026-09-03·CVSS 9.8
CVE-2026-20212 [CRITICAL] Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwardin
2026-09-02
Published