Cisco IOS XR Has No Workaround—Every Release Needs an SMU Check

Cisco issued version 1.3 of its IOS XR security-hardening advisory on September 4, 2026, following the initial September 2 publication. The updated Cisco advisory says every IOS XR release, including IOS XR7 (LNT), is affected regardless of configuration; it groups the findings under seven CVE IDs, provides release-specific SMU information and states that no workaround is available.
That makes version identification—not a configuration change—the starting point for remediation. TechRadar’s September 4 report identifies CVE-2026-20274 and CVE-2026-20279 as the two critical IOS XR groups, each with a maximum CVSS score of 9.8, and distinguishes them from CVE-2026-20212, a separate critical issue affecting certain Nexus 9000 switches.
Start with the installed train, not the configuration

The advisory’s scope does not depend on an optional service being enabled. Disabling a protocol, changing an access list or otherwise hardening the configuration therefore cannot establish that an IOS XR device is unaffected.
Run show version and record the complete release and hardware platform for each device. If the output contains “LNT,” the device is running IOS XR7. Record the active package set with show install active summary; Cisco’s SMU documentation explains that an SMU is built for a particular release and component and is specific to the platform.
- Capture the exact IOS XR release, LNT status and hardware platform with show version.
- Inventory active packages with show install active summary.
- Locate the installed train in the fixed-release table.
- Match the platform and affected functional areas to the listed SMU identifiers.
- After activation, verify the active package set instead of treating a completed download as proof of remediation.
Release availability determines the immediate path

The fixed-release table separates trains with SMUs available now, trains awaiting SMUs and future releases that will contain the fixes directly. A listed base release is not necessarily sufficient on its own: where the table says SMUs are available, the applicable packages must also be installed.
- 7.x: SMUs are available for 7.3.2 on the NCS 1002 optical platform, plus 7.9.2, 7.9.21, 7.10.2, 7.11.2 and 7.11.21.
- 24.x: SMUs are available for 24.2.2, 24.2.21 and 24.4.2. Packages for 24.1.2 and 24.3.2 are forthcoming.
- 25.x: SMUs are available for 25.2.21, for 25.4.1 on the specified optical platforms and for 25.4.2 on non-optical platforms. Packages for 25.1.2 and 25.2.2 are forthcoming.
- 26.x: SMUs are available for 26.1.2 and 26.2.1. Future releases 26.2.2 and 26.3.1 are identified as the first fixed releases that will not require SMUs.
The optical qualifications are narrow: 7.3.2 coverage is limited to NCS 1002, while the listed 25.4.1 coverage applies only to NCS 1001, NCS 1004 and NCS 1010. An absent train is not evidence that it is safe; operators needing packages for an unlisted release are directed to open a TAC service request or contact their support organization.
Functional areas require a second match

The release table identifies a viable destination, but it does not by itself produce a complete installation set. The functional-area matrix must then be checked against the exact release and platform. Its identifiers are lookup keys for locating SMUs, not Cisco bug IDs, and not every package applies to every combination.
- IOS XR7 platform coverage: all LNT releases and platforms map to CSCwv19790.
- BGP: releases in 7.10 and earlier trains, along with 26.2.1, are marked not vulnerable for this functional area; other combinations map to CSCwu14807.
- IS-IS: releases 25.4.1 and 25.4.2 require CSCwu13271 and CSCwv19171; 26.1.2 and 26.2.1 use CSCwv19171; other combinations use CSCwv45645 and CSCwv19171.
- OSPF and transport: OSPF maps to CSCwv40741 and CSCwv19171, MPLS to CSCwu14825, and MPLS-TE to CSCwv40753.
- Segment routing: IPv4-only or combined IPv4/IPv6 deployments map to CSCwv38342. IPv6-only mappings vary by release and platform; 26.1.2 and 26.2.1 are marked not vulnerable in that functional area.
- Services and provisioning: crypto-ike maps to CSCwv19170, gRPC to CSCwt41683, IP-SLA to CSCwv19173 and TCP Authentication Option to CSCwv36143. Zero Touch Provisioning is marked not vulnerable on 26.2.1 and maps to CSCwu36622 elsewhere.
This matrix is a triage aid rather than a universal manifest. The September 4 revision also superseded several earlier identifiers and clarified the entries for 26.1.2 and 26.2.1, so package-selection records should retain the advisory revision used for the change.
The Nexus mitigation does not transfer to IOS XR
CVE-2026-20212 belongs to a separate advisory for Nexus 9000 switches equipped with a Silicon One ASIC. Infrastructure access-list mitigations discussed for that issue do not constitute a workaround for the seven IOS XR CVE groups. Combining the two products into one patching decision risks leaving IOS XR devices exposed.
The current IOS XR advisory says the vulnerabilities were found through internal testing and that PSIRT is not aware of public announcements or malicious use. Its supported response nevertheless remains unchanged: identify the deployed train, select a release with applicable SMUs, match every required package to its platform and functional area, or move to a designated future release that incorporates the fixes.
Package availability is the remaining constraint. Deployments on trains with forthcoming SMUs must await updated entries or work through support; deployments already covered by the table can proceed only with the release- and platform-specific package set.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.