news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans les produits Cisco (03 septembre 2026)

CriticalCVSS 9.8
Summary

Cisco has announced multiple security vulnerabilities across several of its networking products, including IOS XR and SIP software. These vulnerabilities could allow attackers to execute code remotely, cause denial-of-service attacks, and bypass security policies. The affected products range from network switches to IP phones, and require immediate patching to mitigate the risk.

Cisco has identified and disclosed multiple security vulnerabilities affecting various networking products. These vulnerabilities could be exploited to achieve remote code execution, trigger denial-of-service conditions, and circumvent security policies. The affected products include IOS XR Software Train versions 24.1.x through 26.3.x, as well as SIP Software versions 11.0.x and earlier, and various IP Phone series. Specifically, the vulnerabilities are present in the IOS XR software, impacting devices like Cisco Nexus 9000 Series Switches. The vulnerabilities are linked to CVE-2026-20212, CVE-2026-20274, CVE-2026-20275, CVE-2026-20276, CVE-2026-20277, CVE-2026-20278, CVE-2026-20279, and CVE-2026-20280. The vulnerabilities are impacting a wide range of Cisco products, including IP phones and network switches. Cisco recommends referring to their security advisory for detailed information and patching instructions. The advisory links to the relevant security bulletins and CVE records.

Read the full article at CERT-FR