VYPR
Vypr IntelligenceAI-generatedSep 2, 2026· 11 CVEs

Cisco Systems: 11 Vulnerabilities Disclosed in IOS XR, Secure Email, Nexus 9000, and IP Phones

Cisco Systems addressed 11 vulnerabilities on September 2, 2026, impacting IOS XR, Secure Email, Nexus 9000, and IP Phones, with potential for RCE and plaintext recovery.

Key findings

  • Cisco disclosed 11 vulnerabilities on September 2, 2026, across IOS XR, Secure Email, Nexus 9000, and IP Phones.
  • Six high and two critical vulnerabilities in Cisco IOS XR Software stem from an internal security review.
  • Medium-severity flaws in Cisco Secure Email could allow plaintext recovery of encrypted emails.
  • A critical vulnerability in Nexus 9000 Series Switches allows for remote code execution with root privileges.
  • A denial-of-service vulnerability affects multiple series of Cisco IP Phones.
  • Cisco has released software updates to address all disclosed vulnerabilities.

On September 2, 2026, Cisco Systems disclosed a significant batch of 11 vulnerabilities affecting multiple product lines, including Cisco IOS XR Software, Cisco Secure Email, Cisco Nexus 9000 Series Switches, and Cisco IP Phones. The disclosures, all published on the same day, highlight critical security weaknesses that could lead to severe impacts, including remote code execution and plaintext recovery of encrypted emails.

A cluster of six high-severity and two critical-severity vulnerabilities were found within Cisco IOS XR Software, stemming from an internal security review. These vulnerabilities, including CVE-2026-20274, CVE-2026-20275, CVE-2026-20276, CVE-2026-20278, CVE-2026-20279, and CVE-2026-20280, all carry CVSS scores of 8.8 or higher, with CVE-2026-20279 and CVE-2026-20274 rated as critical at 9.8. These flaws were addressed through software hardening releases.

Two medium-severity vulnerabilities, CVE-2026-20354 and CVE-2026-20355, affect the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality in Cisco Secure Email. These vulnerabilities are due to insufficient validation of message integrity, potentially allowing an unauthenticated, remote attacker to recover plain text from encrypted emails. Cisco noted that these flaws could enable a man-in-the-middle attack, and affect devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled.

A critical vulnerability, CVE-2026-20212, was identified in the Silicon One integration for Cisco Nexus 9000 Series Switches. This flaw, with a CVSS score of 9.8, could permit an unauthenticated, remote attacker to execute code with root privileges by exploiting accessible TCP ports 43210 and 43211 in the default Layer 3 VRF. This vulnerability was discovered during a Technical Assistance Center support case.

Additionally, a high-severity denial-of-service (DoS) vulnerability, CVE-2026-20281, impacts Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software. This flaw allows an unauthenticated, remote attacker to disrupt the availability of affected devices.

Cisco has released software updates to address these vulnerabilities. Users are strongly advised to consult Cisco's security advisories for specific version information and recommended actions. The coordinated disclosure of these vulnerabilities underscores the importance of timely patching and security reviews for complex network infrastructure.

The batch includes critical vulnerabilities in Cisco IOS XR Software and Nexus 9000 Series Switches, alongside medium-severity flaws in Secure Email that could expose encrypted content. Users are urged to prioritize updates for affected systems to mitigate risks of unauthorized access and data compromise. The disclosure highlights ongoing security efforts by Cisco, including internal reviews and prompt responses to discovered vulnerabilities.

AI-written article. Grounded in 11 CVE records listed below.