Cisco resolved CVE-2026-20274, an unauthenticated memory corruption flaw in IOS XR software that enables crash-loops or remote code execution in telecommunications cores.
Threat actors and Qilin ransomware affiliates are actively weaponizing CVE-2026-20079 in Cisco Secure FMC to bypass web authentication and achieve root command execution.
Cisco disclosed CVE-2026-20212 (CVSS 9.8), an unauthenticated root code execution flaw on Silicon One-based Nexus 9000 datacenter switches due to open debugging ports.