Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-20074

CVE-2026-20074: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityHigh7.4

    High [CVE-2026-20074] Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability

    cisco-sa-isis-dos-kDMxpSzKSource published Source updated

    A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacker could exploit this vulnerability by sending crafted IS-IS packets to an affected device after forming an adjacency. A successful exploit could allow the attacker to cause the IS-IS process to restart unexpectedly, resulting in a temporary loss of connectivity to adver…

    Related products — impact not confirmed
    • Cisco IOS XR Software
    Source-reported affected versions
    • Scope: This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS XR Software and have the IS-IS multi-instance routing feature enabled.
    • Release 7.7 and earlier (first fixed: Not affected)
    • 7.8 — Migrate to a fixed release
    • 7.9 — Migrate to a fixed release

    10 more entries in the full advisory.

    Source-reported fixed versions
    • Not affected
    • 25.2.2
    • 25.3.1
    Mitigation guidance
    • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
    • Release 7.7 and earlier: upgrade to Not affected.
    • Release 7.8: migrate to a fixed release.
    • Release 7.9: migrate to a fixed release.

    5 more entries in the full advisory.

    Workarounds
    • There are no workarounds that address this vulnerability.
    • As a mitigation, configure IS-IS area authentication. This would require an attacker to authenticate successfully to the IS-IS area before they are able to form an adjacency and exploit this vulnerability. For more information on configuring IS-IS authentication, see the IS-IS Authentication section of the Routing Configuration Guide for Cisco NCS 5500 Series Routers, IOS XR Release 24.1.x, 24.…

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery