LATEST View all updates

Cisco IOS XR Critical Update: 26.2.2 and 26.3.1 Fixed Releases Now Available

Cisco now lists IOS XR 26.2.2 and 26.3.1 as fixed releases, changing the remediation path for affected operators.

Network engineer reviewing IOS XR router remediation with a fixed-release security update theme

Signal Brief

  • Cisco's September 11 advisory update makes IOS XR 26.2.2 and 26.3.1 available as fixed releases rather than future releases.
  • Operators on other IOS XR trains may still need Cisco-listed SMUs matched to their exact release, platform and functional area.
  • Cisco lists no workaround and says it is not aware of malicious exploitation at the time of the reviewed advisory.

Cisco has changed the remediation state for its September 2026 IOS XR security hardening advisory. In the September 11 version 2.0 update, Cisco made IOS XR releases 26.2.2 and 26.3.1 available as the first fixed releases containing the advisory’s fixes. That means guidance describing those releases as future versions is now stale.

The important distinction is that this is not a newly disclosed vulnerability event. Cisco originally published the advisory on September 2. The material change on September 11 is that two full fixed-release paths are now available, while operators on other supported release trains may still need Cisco-listed Software Maintenance Upgrades, or SMUs.

What changed in Cisco’s September 11 update

Cisco’s current advisory identifies releases 26.2.2 and 26.3.1 as the first fixed IOS XR releases for the grouped vulnerabilities covered by the advisory. Earlier advisory states treated those releases as forthcoming. For teams that were waiting for a full fixed release instead of applying individual SMUs, that changes the available remediation choice.

The advisory remains rated Critical, with a maximum CVSS score of 9.8. Cisco says all IOS XR releases, including IOS XR7 and LNT-based releases, are affected by vulnerabilities covered by the advisory. That statement should not be read as meaning every listed vulnerability affects every platform or feature in exactly the same way.

How to choose the remediation path

If your supported platform and release path can move to IOS XR 26.2.2 or 26.3.1: review Cisco’s current release documentation and platform compatibility guidance before upgrading. These are now the first full releases Cisco lists as containing the fixes addressed by the advisory.
If you must remain on another supported IOS XR train: use Cisco’s advisory tables to identify the applicable SMU for the exact release, platform and functional area you operate.
If the correct path is unclear: do not assume that the highest-severity vulnerability or one SMU applies identically to every device. Match the deployed software and platform against Cisco’s current advisory before making a production change.

There is no workaround listed

Cisco states that no workarounds are available for the vulnerabilities addressed by this advisory. That makes software remediation the controlling path: either move to an appropriate fixed release or apply the relevant Cisco-provided SMUs for the deployed train and platform.

Cisco also says it is not aware of malicious exploitation of the vulnerabilities described in the advisory. That is the vendor’s current knowledge state, not a guarantee that exploitation cannot occur later. Any future Cisco revision, exploitation evidence or CISA Known Exploited Vulnerabilities addition would materially change the risk picture and should be treated as a same-URL update.

What network teams should check now

First identify the exact IOS XR release and hardware platform in production. Then compare that environment with Cisco’s current affected-and-fixed release guidance. If 26.2.2 or 26.3.1 is an appropriate supported destination, review the related release notes and operational requirements before change deployment. If not, use Cisco’s SMU guidance for the applicable train rather than assuming the two new full releases are suitable for every environment.

The key update is simple: the Cisco IOS XR 26.2.2 26.3.1 fixed release path is now real rather than forthcoming. The remaining decision is environment-specific, because the correct remediation still depends on the release train, platform and functional area actually in use.

Verification note

ThePulseSignal reviewed Cisco’s current PSIRT advisory, including its version history and fixed-release guidance, and cross-checked Cisco release documentation for IOS XR 26.2.2 and 26.3.1. TPS did not test individual routers or validate organization-specific upgrade compatibility.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led cybersecurity article for informational and editorial guidance. Cisco IOS XR remediation depends on the exact release, platform and functional area in use, and Cisco may revise fixed-release or SMU guidance. TPS has not tested individual deployments. Before changing production network software or applying an SMU, verify the controlling current Cisco advisory, release documentation and platform-specific guidance.