Skip to main content

Cisco vulnerabilities September 2026: critical flaws in IOS XR and Nexus 9000

Cisco has released security advisories with a score of 9.8 out of 10 affecting IOS XR and Nexus 9000 equipment with Silicon One. The Cisco vulnerabilities of September 2026 necessitate a review of network equipment patching, not just server maintenance.

CybersecuritySeintec team2-3 min read
Cisco vulnerabilities September 2026: critical flaws in IOS XR and Nexus 9000

News summary

The manufacturer has reported vulnerabilities with a severity of 9.8 out of 10 in IOS XR software and Nexus 9000 switches equipped with Silicon One. A score of this level means, in practical terms, that the flaw can be exploited remotely and with low complexity.

The peculiarity of network equipment is that it rarely enters regular update cycles. Servers and workstations are patched with a degree of discipline; switches and routers, by contrast, have often been running for years without being touched because any change implies a service window and a risk of downtime.

This reasoning, while understandable, leaves a significant blind spot: a compromised network device does not just affect one application, it affects everything that passes through it. It allows for traffic observation, route alteration, or serving as a stable foothold to move through the infrastructure without being detected by tools focused on the workstation.

Our recommendation is to prioritise by exposure rather than severity. A device with a management plane accessible from the internet or the user network is urgent. One with management restricted to a dedicated network allows for more orderly planning.

While the update is being planned, mitigation measures provide real value: limiting management plane access to specific addresses, disabling unused services, reviewing local accounts, and enabling event logging to a central system.

And a methodological note: it is advisable to know at all times which version each device is running. Many organisations discover they are unaware of this on the very day a critical alert is published, turning a task of hours into a project of weeks.

Source: Cisco — 2 September 2026

What happened

Cisco disclosed vulnerabilities with a severity of 9.8 out of 10 in IOS XR software and in Nexus 9000 switches fitted with Silicon One. That score means, in practice, that the flaw can be exploited remotely with low complexity.

Network equipment rarely follows the usual update cycles: servers and endpoints are patched with some discipline, while switches and routers often run untouched for years because any change involves a service window and the risk of an outage.

What it teaches a mid-sized business

A compromised network device doesn't affect one application; it affects everything that passes through it: it can allow traffic observation, route manipulation, or serve as a stable foothold to move through the infrastructure unseen by endpoint-focused tools.

Many organisations discover they don't know what version each device runs on exactly the day a critical advisory is published, turning a task of hours into a project of weeks.

What to review

Priorities and mitigations while the update is planned:

  • Prioritise by exposure: urgent if the management plane is reachable from the internet or the user network.
  • Restrict management-plane access to specific addresses and disable unused services.
  • Review local accounts and enable event logging to a central system.
  • Keep an up-to-date inventory of which version each network device is running.

Frequently Asked Questions

What does a CVSS score of 9.8 mean?
That the vulnerability is critical: usually exploitable remotely, without authentication and with low complexity, with high impact on confidentiality, integrity and availability.
Can network equipment be updated without cutting service?
In redundant architectures, yes, by updating node by node and rerouting traffic. Without redundancy, plan a short window with a saved configuration and a tested rollback plan.
Which specific devices are affected?
Systems running IOS XR software and Nexus 9000 switches fitted with Silicon One, according to the advisory published by Cisco.

Keeping network equipment updated and configurations under control is part of the service, not an extra. At Seintec, we manage business connectivity and network electronics patching with scheduled windows. Consult us.

Contact Seintec

Related service

Connectivity and Telecommunications

Fibre, radio link, and satellite to keep your business connected, with redundancy and a single point of contact.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.