Answer in brief
CVE-2026-20280 records a Unknown severity vulnerability in Cisco IOS XR Software Security Hardening Release: September 2026. The current sources do not mark it as known exploited. The current feed maps Cisco/Cisco IOS XR Software (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Cisco/Cisco IOS XR Software (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco IOS XR Softwaregeneric | 6.5.29 || 7.0.1 || 6.5.26 || 6.5.25 || 6.5.28 || 6.5.90 || 7.1.1 || 7.0.90 || 6.7.1 || 7.0.2 || 7.1.15 || 7.2.1 || 7.1.2 || 6.7.2 || 7.0.11 || 7.0.12 || 7.0.14 || 7.1.25 || 7.2.12 || 7.3.1 || 7.1.3 || 6.7.3 || 7.4.1 || 7.2.2 || 6.7.4 || 6.5.31 || 7.3.15 || 7.3.16 || 6.8.1 || 7.4.15 || 6.5.32 || 7.3.2 || 7.5.1 || 7.4.16 || 7.3.27 || 7.6.1 || 7.5.2 || 7.8.1 || 7.6.15 || 7.5.12 || 7.8.12 || 7.3.3 || 7.7.1 || 6.8.2 || 7.3.4 || 7.4.2 || 6.7.35 || 6.9.1 || 7.6.2 || 7.5.3 || 7.7.2 || 6.9.2 || 7.9.1 || 7.10.1 || 7.8.2 || 7.5.4 || 6.5.33 || 7.8.22 || 7.7.21 || 7.9.2 || 7.3.5 || 7.5.5 || 7.11.1 || 7.9.21 || 7.10.2 || 24.1.1 || 7.6.3 || 7.3.6 || 7.5.52 || 7.11.2 || 24.2.1 || 24.1.2 || 24.2.11 || 24.3.1 || 24.4.1 || 24.2.2 || 7.8.23 || 7.11.21 || 24.2.20 || 24.3.2 || 24.4.10 || 6.5.35 || 25.1.1 || 24.4.2 || 24.3.20 || 24.4.15 || 25.2.1 || 6.5.351 || 25.1.2 || 24.3.30 || 25.3.1 || 6.5.352 || 24.4.30 || 24.2.21 || 25.4.1 || 25.2.2 || 25.2.15 || 7.2.0 || 7.0.0 || 25.2.30 || 6.5.353 || 26.1.1 || 25.1.30 || 25.3.15 || 26.2.100 || 25.4.2 || 26.2.1 || 25.4.30 || 26.1.2 || 25.4.201 || 26.2.101 | Not reported |
Published upstream
Sep 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 2, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.
Quoted source text, attributed separately from HOL analysis.