Back to vendor advisories
Cisco Security Advisoriescisco-sa-notice-f2SiMFxl

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco IOS XR Software Security Hardening Release: September 2026 CVE-2026-20277CVE-2026-20278CVE-2026-20280CVE-2026-20279CVE-2026-20276CVE-2026-20275CVE-2026-20274 Critical 9.8 Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability CVE-2026-20212 Critical 9.8 Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability CVE-2026-20281 High 7.5 Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities CVE-2026-20355CVE-2026-20354 Medium 5.9 To remediate the vulnerabilities that were disclosed on September 2, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery. Security Impact Rating: Informational

InformationalCVSS not listedInformational severity
Scope

What the vendor says is affected

The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.

Update history

What changed in later vendor updates

SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.

    • The vendor changed the advisory summary.
    • Added CVEs: CVE-2026-20212, CVE-2026-20281.
    • The vendor changed its remediation guidance.
Timeline

When this advisory changed

  1. Added to SecurityAlert

    We collected the advisory from the official source.

  2. Published by Cisco

    The publication date reported by the vendor.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.

Vulnerabilities

CVEs named in this advisory