Cisco released patches for multiple vulnerabilities in its IOS XR network operating system. Two critical flaws carry a severity score of 9.8 out of 10. These vulnerabilities impact all releases of the software and could allow remote attackers to gain root access to routers.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog. Cisco confirmed active exploitation of this flaw began in August 2026. Federal agencies must apply the necessary patches by September 12, 2026.