Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-20074

28
FAUCET Score

CVE-2026-20074 is a high-severity denial of service vulnerability affecting the IS-IS multi-instance routing feature in Cisco IOS XR Software, caused by insufficient input validation. An unauthenticated, adjacent attacker can exploit this by sending crafted IS-IS packets after forming an adjacency, leading to an unexpected restart of the IS-IS process. This results in a temporary loss of connectivity and a denial of service condition, with a CVSS score of 7.4. There is currently no public exploit code, nor is it listed in the CISA KEV catalog, indicating no active exploitation or significant community attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.8.0, < 25.2.2CPE matchmatch criteria
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
25.3.0CPE matchmatch criteria
cpe:2.3:o:cisco:ios_xr:25.3.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 2nd percentile among its peer group of 1,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

jenkinspatch availablevia llm_extracted
Fixed in: 1.0
View patch
opensipspatch availablevia llm_extracted
Fixed in: 1.0
View patch
wiresharkpatch availablevia llm_extracted
Fixed in: 1.0
View patch
ciscoworkaround availablevia nvd_reference
View patch
h2ovendor investigatingvia llm_extracted
jellyfinvendor investigatingvia llm_extracted
View patch

Vendor Advisories (5)

jenkinsllm-jenkins-a2941a527417a8b7HIGH

Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability

Mar 11, 2026
wiresharkllm-wireshark-eb2d43434293bb2aHIGH

Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability

Mar 11, 2026
h2ollm-h2o-6e09c01c947e7572HIGH

Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability

Mar 11, 2026
jellyfinllm-jellyfin-51b4fb499f23c481HIGH

Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability

Mar 11, 2026
opensipsllm-opensips-ecf873647477dc04HIGH

Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability

Mar 11, 2026

References

sec.cloudapps.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-isis-dos-kDMxpSzK
MitigationVendor Advisory