CVE-2026-20074 is a high-severity denial of service vulnerability affecting the IS-IS multi-instance routing feature in Cisco IOS XR Software, caused by insufficient input validation. An unauthenticated, adjacent attacker can exploit this by sending crafted IS-IS packets after forming an adjacency, leading to an unexpected restart of the IS-IS process. This results in a temporary loss of connectivity and a denial of service condition, with a CVSS score of 7.4. There is currently no public exploit code, nor is it listed in the CISA KEV catalog, indicating no active exploitation or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.8.0, < 25.2.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* | ||
25.3.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:25.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
Mar 11, 2026Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
Mar 11, 2026Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
Mar 11, 2026Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
Mar 11, 2026Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
Mar 11, 2026