Cisco has changed the remediation state for its September 2026 IOS XR security hardening advisory. In the September 11 version 2.0 update, Cisco made IOS XR releases 26.2.2 and 26.3.1 available as the first fixed releases containing the advisory’s fixes. That means guidance describing those releases as future versions is now stale.
The important distinction is that this is not a newly disclosed vulnerability event. Cisco originally published the advisory on September 2. The material change on September 11 is that two full fixed-release paths are now available, while operators on other supported release trains may still need Cisco-listed Software Maintenance Upgrades, or SMUs.
What changed in Cisco’s September 11 update
Cisco’s current advisory identifies releases 26.2.2 and 26.3.1 as the first fixed IOS XR releases for the grouped vulnerabilities covered by the advisory. Earlier advisory states treated those releases as forthcoming. For teams that were waiting for a full fixed release instead of applying individual SMUs, that changes the available remediation choice.
The advisory remains rated Critical, with a maximum CVSS score of 9.8. Cisco says all IOS XR releases, including IOS XR7 and LNT-based releases, are affected by vulnerabilities covered by the advisory. That statement should not be read as meaning every listed vulnerability affects every platform or feature in exactly the same way.
How to choose the remediation path
There is no workaround listed
Cisco states that no workarounds are available for the vulnerabilities addressed by this advisory. That makes software remediation the controlling path: either move to an appropriate fixed release or apply the relevant Cisco-provided SMUs for the deployed train and platform.
Cisco also says it is not aware of malicious exploitation of the vulnerabilities described in the advisory. That is the vendor’s current knowledge state, not a guarantee that exploitation cannot occur later. Any future Cisco revision, exploitation evidence or CISA Known Exploited Vulnerabilities addition would materially change the risk picture and should be treated as a same-URL update.
What network teams should check now
First identify the exact IOS XR release and hardware platform in production. Then compare that environment with Cisco’s current affected-and-fixed release guidance. If 26.2.2 or 26.3.1 is an appropriate supported destination, review the related release notes and operational requirements before change deployment. If not, use Cisco’s SMU guidance for the applicable train rather than assuming the two new full releases are suitable for every environment.
The key update is simple: the Cisco IOS XR 26.2.2 26.3.1 fixed release path is now real rather than forthcoming. The remaining decision is environment-specific, because the correct remediation still depends on the release train, platform and functional area actually in use.
Verification note
ThePulseSignal reviewed Cisco’s current PSIRT advisory, including its version history and fixed-release guidance, and cross-checked Cisco release documentation for IOS XR 26.2.2 and 26.3.1. TPS did not test individual routers or validate organization-specific upgrade compatibility.


