Jessica Entwistle
September 4 2026
The Register reports that Cisco has released security updates addressing multiple critical vulnerabilities across its IOS XR and Nexus 9000 product lines. The most severe flaw, CVE-2026-20212, affects Silicon One-based Nexus 9000 switches and carries a CVSS score of 9.8, allowing unauthenticated remote attackers to execute code as root. Cisco discovered so many vulnerabilities during internal security testing of IOS XR that it bundled seven CVEs into a single hardening release, including two rated 9.8. Significantly, there are no workarounds available for any affected IOS XR version, and the Nexus 9000 vulnerability can only be mitigated, not fully fixed, in current releases.
Cisco Nexus 9000 switches are widely deployed in enterprise data centres and critical network segments across the UK, whilst IOS XR powers many service provider and large enterprise networks. The severity of CVE-2026-20212 cannot be understated: an unauthenticated attacker who successfully exploits this vulnerability gains root-level access to affected switches, meaning they could completely compromise the device, intercept traffic, disrupt operations, or use it as a pivot point for further attacks. The absence of workarounds for the IOS XR vulnerabilities means patching is the only effective defence. These are not theoretical risks; they affect core infrastructure that underpins business operations, and the vulnerabilities are now publicly documented, which typically accelerates exploitation attempts. For organisations running affected devices, the operational risk is immediate and significant.
UK businesses running Cisco network equipment should immediately review their infrastructure to identify which devices are affected by these vulnerabilities. Prioritise patching within your maintenance windows, and where immediate patching is not possible, consider whether affected devices can be isolated from untrusted networks or whether additional monitoring can detect unusual activity such as unexpected configuration changes or unauthorised access attempts. Ensure your asset inventory is current enough to identify which systems need attention, and confirm that your vulnerability management process has clear ownership and escalation paths for critical infrastructure updates. If you rely on managed service providers for network management, confirm they are aware of these updates and have a plan to apply them. This is also a useful moment to review whether your network segmentation would limit the impact of a compromised switch, and whether your monitoring would detect lateral movement following a successful exploit.
Source: The Register