Cybersecurity 6 min read

Cisco Found Seven Flaws in Every IOS XR Release, and Says AI Models Helped

Two at CVSS 9.8, unauthenticated and network-reachable, none known to be exploited. The advisory names frontier AI models as part of how they were found, which vendors do not usually do.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 7 Sep 2026, 4:59 AM (SGT)
Share:
Close-up of red, orange and yellow network patch cables with their RJ45 connectors fanned out against a white background. Close-up of red, orange and yellow network patch cables with their RJ45 connectors fanned out against a white background. Photo by fotofixautomat on Pixabay
Advertisement

7 SEP 2026 — Cisco has published seven vulnerabilities in IOS XR, two of them at CVSS 9.8, affecting all releases of the software regardless of device configuration. It found them itself, and its advisory says the review used existing testing processes as well as frontier AI models. That last clause is the news.

What the advisory says

The seven carry identifiers CVE-2026-20274 through CVE-2026-20280. Two sit at 9.8. Those are an improper control of a resource through its lifetime and an improper access control, both reachable over the network with no authentication. The remaining five run from 8.2 to 8.8 and cover resource calculation errors, improper neutralisation, exception handling and insufficient randomness in a protection mechanism.

Cisco's product security incident response team says it is not aware of any public announcements or malicious use of any of them. They were found internally, not reported by a researcher and not discovered in an incident.

Remediation is by software maintenance update for most existing releases, with versions 26.2.2 and 26.3.1 folding the fixes in so no patch is needed.

7Vulnerabilities disclosed, two of them at CVSS 9.8
AllIOS XR releases affected, regardless of configuration
0Known to be exploited or publicly disclosed
Frontier AINamed in the advisory as part of how they were found

A vendor saying which tool found the bugs

Labs have spent this year publishing models trained to find and exploit vulnerabilities, and arguing about who should be allowed to run them. We have covered the releases and the access programmes: CrowdStrike's Red Tempest, and the week when three labs shipped cyber models behind three vetting programmes.

The argument for those programmes was always that the capability would be used defensively by the people who own the code. This advisory is the first time a major network vendor has said in a security document that frontier AI models were part of finding flaws in its own flagship router operating system.

That small sentence carries a large implication. Vendors rarely disclose their bug-hunting methodology, and this one converts an abstract argument about dual use into a dated artefact.

What it does not tell you

Which models, whose, at what access tier, and how much of the seven came from them rather than from the existing testing processes named in the same sentence. The advisory says both were used and does not apportion.

The apportionment is the whole question. If frontier models found the two 9.8s, the capability works on production code at scale. If they found the low end while conventional fuzzing found the rest, it is a much smaller claim wearing the same words.

There is also no false-positive rate, no measure of how much engineer time the review consumed, and no statement about whether the models were run under one of the vetted-access programmes or on Cisco's own infrastructure. Without those numbers, the disclosure is a signal of intent rather than a reproducible result.

Read the scope line, not the count

Coverage has settled on three critical vulnerabilities. The advisory lists seven, and two rather than three are at 9.8. The rest are high rather than critical, which is a real distinction and not the one being made.

More important than either count is the scope. All releases of Cisco IOS XR Software, including IOS XR7, are affected regardless of device configuration. No hardening posture, no disabled feature, no configuration choice takes an operator out of scope.

IOS XR runs on service provider core and edge routers. The exposure is not a large number of devices but a small number of core and edge routers carrying immense volumes of other people's traffic, and two of these flaws are unauthenticated and network-reachable.

Advertisement

Two weeks after somebody was actually inside

The timing invites a connection that should be stated carefully. On 2 September we reported Fire Ant operating on IOS XR routers, abusing TACACS and GRE tunnels, in research from Sygnia.

Nothing in this advisory refers to that activity, and Cisco says these seven are not known to have been used maliciously. Treating the two as one story would be wrong.

A narrower reading still matters. The platform is under active attention from a capable intrusion set, and its vendor has just disclosed seven previously unknown flaws in every release of it, two of which need no credentials. Those two facts do not have to be causally linked to belong in the same patch decision.

What to do, and what to watch

The operational answer is unglamorous. Identify IOS XR devices, check the release against the advisory's fixed-release table, apply the maintenance updates, and plan the move to 26.2.2 or 26.3.1 so the patches stop being a per-release exercise.

The question now is whether other vendors follow the disclosure. If Juniper, Arista or Nokia start naming AI-assisted review in advisories, a defensive norm forms quickly and the vetted-access argument acquires its evidence. If Cisco's sentence stays unique, it was a marketing decision rather than the start of a practice.

The uncomfortable corollary holds either way. If frontier models can find unauthenticated remote flaws in a mature, heavily audited router operating system, then the same class of capability applied by someone without the source code and without a disclosure policy is the risk the access programmes exist to manage. This advisory is the encouraging half of that sentence.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement