Cisco has released patches for eight vulnerabilities in its IOS XR operating system, a software used in many of its networking devices. Among these, three are classified as critical, with a severity rating of 9.8 out of 10, the highest possible score. While Cisco has not found evidence that any of these flaws have been exploited in the wild, it strongly urged customers to apply the patches immediately. The vulnerabilities could allow attackers to exploit devices without authentication, bypass access controls, or execute arbitrary code. The company published two advisories on September 2 detailing the vulnerabilities. The first advisory listed seven flaws, including two critical ones: CVE-2026-20274 and CVE-2026-20279. Both vulnerabilities are network-based and can be exploited with low complexity, requiring no user interaction or authentication. CVE-2026-20274 involves improper control of a resource during its lifetime, while CVE-2026-20279 relates to improper access control. These issues affect all versions of Cisco IOS XR Software, including the newer Cisco IOS XR7 (LNT) Software, regardless of device configuration. Cisco confirmed there are no workarounds, and applying the provided patches is the only way to address the risks. A third critical vulnerability, CVE-2026-20212, was disclosed in a separate advisory. This flaw allows attackers to connect to an affected device and send specially crafted input that could be executed as code, even without root access. Exploitation of this vulnerability could also cause the S1HAL process to crash, potentially leading to a device reload. This issue affects Cisco Nexus 9000 Series Switches that include a Silicon One ASIC, a type of specialized hardware used in networking equipment. Cisco provided some temporary mitigation options for CVE-2026-20212, including the use of infrastructure access control lists (iACLs) to restrict traffic to only necessary management and control plane communications. Alternatively, iACLs could be configured to explicitly block all TCP packets targeting specific ports (43210 or 43211) on locally configured IP addresses. However, Cisco emphasized that these are only temporary solutions, and applying the official patch remains the most effective way to secure affected devices.