Skip to main content

Cisco vulnerabilities September 2026: critical flaws in IOS XR and Nexus 9000

Cisco has published security advisories scored 9.8 out of 10 affecting IOS XR and Nexus 9000 switches with Silicon One. The Cisco vulnerabilities of September 2026 mean reviewing patching for network equipment, not just servers.

CybersecuritySeintec Team2-3 min read
Cisco vulnerabilities September 2026: critical flaws in IOS XR and Nexus 9000

News summary

The vendor has reported vulnerabilities with a severity of 9.8 out of 10 in IOS XR software and in Nexus 9000 switches fitted with Silicon One. A score at that level means, in practical terms, that the flaw can be exploited remotely and with little complexity.

The peculiarity of network equipment is that it rarely enters the usual update cycles. Servers and endpoints are patched with some discipline; switches and routers, by contrast, often run untouched for years because any change means a service window and a risk of interruption.

That understandable reasoning leaves a significant blind spot: a compromised network device does not affect one application, it affects everything passing through it. It allows traffic to be observed, routes to be altered, or serves as a stable foothold for moving across the infrastructure unseen by endpoint-focused tools.

Our recommendation is to prioritise by exposure before severity. A device whose management plane is reachable from the internet or from the user network is urgent. One with management restricted to a dedicated network allows more orderly planning.

While the upgrade is being planned, mitigations have real value: restricting management plane access to specific addresses, disabling unused services, reviewing local accounts and sending event logs to a central system.

A methodological note: you should know at all times which version each device is running. Many organisations discover they do not know on exactly the day a critical advisory is published, which turns a task of hours into a project of weeks.

Source: Cisco 2 September 2026

Why this matters to a company operating in Spain

The threat landscape affecting Spanish companies no longer distinguishes by size. Attacks are automated, sold as a service, and seek the shortest path: a reused credential, an unpatched server, or a provider with poorly controlled remote access. For an SME, the difference between a minor scare and a multi-day shutdown almost always depends on decisions made before the incident.

That is why every industry update should be read in operational terms: which specific controls would have prevented the problem, what evidence must be preserved, and who makes the decision when the clock is ticking. This is the approach we apply to managed cybersecurity projects at Seintec.

Real business impact

Before deciding on an investment, it is advisable to identify what is at stake. In connectivity and telecommunications projects, we typically review these four areas with management and the IT manager:

  • Operational disruption: orders, invoicing, or production halted while systems are restored.
  • Loss or exposure of personal data, with a mandatory 72-hour notification requirement to the AEPD.
  • Hidden cost of recovery: overtime, external hiring, and loss of client trust.
  • Contractual and compliance requirements (ENS, NIS2, ISO 27001) that demand evidence, not intentions.

Five-step action plan

A useful plan fits on one page. This is the roadmap we apply with our clients to move from news to measurable improvement, without disrupting daily operations:

  • Inventory network equipment with model, software version and date of last update.
  • Cross-check the inventory against the vendor's advisories and flag affected devices.
  • Prioritise by management plane exposure and by the criticality of the traffic each device carries.
  • Apply immediate mitigations: restricted management access, unnecessary services disabled and centralised logging.
  • Plan the upgrade in an agreed window, with the configuration backed up and a rollback plan.

Key indicators you should be measuring

What is not measured is not managed. These indicators allow you to verify if the technological investment is yielding results and serve as the basis for the periodic reports we deliver to our clients:

  • Percentage of network devices running a supported software version.
  • Days from publication of a critical advisory to applying or mitigating it.
  • Number of devices with a management plane reachable from outside the administration network.
  • Coverage of the network inventory against all devices in production.

How we approach it at Seintec: Connectivity and Telecommunications

Fibre, radio link and satellite to keep your business online, with redundancy and a single point of contact. We operate from our own datacenter in Spain, with a certified technical team and a single point of contact who knows your infrastructure, so you do not have to explain your environment every time an incident arises.

These are the capabilities we bring to the table in a connectivity and telecommunications project:

  • FTTH fibre: High-performance connectivity for offices and businesses wherever the coverage available at the site allows it.
  • Dedicated fibre: Reserved capacity and business-grade terms for critical environments, subject to feasibility and to the provider used.
  • Radio link: Professional wireless connectivity for sites where fibre is not viable, or as an independent second route.
  • Starlink for business: LEO satellite internet using Starlink technology for sites without fibre or as an independent secondary link.
  • Redundant connectivity: Two different technologies combined to reduce dependence on a single connection and a single route.
  • Automatic failover: Switchover to the secondary line when the configured architecture detects that the primary is down.

What you gain by working with a technology partner

Outsourcing does not mean losing control: it means gaining predictability, coverage, and independent technical insight. These are the benefits our clients highlight:

  • A single point of contact: If something breaks, you call Seintec. We coordinate the diagnosis, follow up with the carrier or provider through to resolution and keep you informed.
  • Supervised installation: Our technical team coordinates and supervises the installation and validates its integration with the company's infrastructure before signing it off.
  • The right technology for each case: We don't force every project into the same connection: FTTH, dedicated fibre, radio link or satellite depending on location, coverage and criticality.
  • Realistic continuity: We design redundant architectures to reduce the risk of a single fault leaving the company offline, without promising absolute availability.

Frequently Asked Questions

What does a CVSS score of 9.8 mean?
That the vulnerability is critical: normally exploitable remotely, without authentication and with low complexity, with high impact on confidentiality, integrity and availability. It requires priority action.
Can network equipment be upgraded without interrupting service?
In redundant architectures, yes, upgrading node by node and diverting traffic. Where there is no redundancy, a short window is planned with the configuration backed up and a tested rollback plan.
How do I know if my company is truly protected?
With evidence: EDR coverage, two-factor authentication on all remote access, immutable copies, and a recently tested restoration. If any of these four points are not confirmed, there is a real risk of prolonged downtime.
Where should a company wanting to address connectivity and telecommunications begin?
With an audit of the current environment. At Seintec, we perform an initial no-cost review that identifies risks, dependencies, and priorities, resulting in a phased plan with fixed deadlines and budgets.
Is it necessary to halt business operations during the project?
No. We plan migrations and changes within agreed windows, with prior pilot tests and rollback options, ensuring disruption is minimal or non-existent for users.
What type of companies do you serve?
SMEs and mid-market companies in sectors such as industry, automotive, logistics, retail, legal, and healthcare, with both on-premises and hybrid cloud infrastructure.
What coverage and response times (SLA) do you offer?
Support from Monday to Friday, 09:00 to 18:00, and 24x7 emergencies 365 days a year, with a committed response SLA and a 99.98% service SLA in 2025.

Keeping network equipment updated and its configuration under control is part of the service, not an extra. At Seintec we manage business connectivity and network equipment patching in planned windows. Get in touch.

Contact Seintec

Related service

Connectivity and Telecommunications

Fibre, radio link and satellite to keep your business online, with redundancy and a single point of contact.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.