Cisco has disclosed seven vulnerabilities impacting its networking operating system, IOS XR, with two rated as critical severity, according to a recent report by SDx Central.The vulnerabilities, labeled CVE-2026-20274 through CVE-2026-20280, were discovered during an internal security review. The two critical flaws, CVE-2026-20274 and CVE-2026-20279, stem from improper resource control via buffering issues and incorrect certificate validation with missing authentication, respectively. Additionally, a separate bug, CVE-2026-20212, affects the Silicon One integration in the Nexus 9000 data center switch. This vulnerability could allow an unauthenticated, remote attacker to execute code with root privileges by exploiting exposed TCP ports 43210 and 43211 in the default Layer 3 virtual routing and forwarding. Cisco advises users to upgrade affected Nexus 9000 switches to a fixed Cisco NX-OS release to mitigate these risks.Source: SDx Central