Full Report
Cisco security advisory (AV26-876)
Analysis Summary
# Vulnerability: Cisco Multiple Product Security Vulnerabilities (September 2026)
## CVE Details
*Note: Specific CVE IDs and CVSS scores are detailed within the individual sub-advisories linked in the report.*
* **Remote Code Execution (Nexus 9000):** CVE-2026-XXXXX (Pending specific ID)
* **CVSS Score:** Critical/High (Estimated based on RCE classification)
* **CWE:** CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) / CWE-94 (Code Injection)
* **Denial of Service (IP Phones):** CVE-2026-XXXXX
* **CVSS Score:** Medium/High
* **CWE:** CWE-400 (Uncontrolled Resource Consumption)
## Affected Systems
* **Cisco Nexus 9000 Series Switches:** Specific models utilizing Silicon One ASICs.
* **Cisco IOS XR Software:** Multiple versions (Security Hardening Release).
* **Cisco Desk Phone 9800 Series & Video Phone 8875:** Versions prior to 5.0(1).
* **IP Phone 7800 & 8800 Series:** Versions prior to 14.4(1)SR3.
* **IP Phone 8845 & 8865:** Versions prior to 14.4(1)SR4.
* **Wireless IP Phone 8821:** Versions prior to 11.0(6)SR8.
## Vulnerability Description
This advisory covers three primary security issues:
1. **Nexus 9000 RCE:** A vulnerability in the Silicon One ASIC implementation that could allow a remote, unauthenticated attacker to execute arbitrary code with elevated privileges.
2. **IOS XR Hardening:** A comprehensive security hardening update addressing multiple potential vectors within the IOS XR software stack.
3. **IP Phone SIP DoS:** A flaw in the Session Initiation Protocol (SIP) stack of various Cisco IP phones. An attacker could send crafted SIP packets to the device, causing a reload or a permanent Denial of Service (DoS) condition.
## Exploitation
* **Status:** Not exploited (Current report indicates advisory phase; no active "in the wild" exploitation confirmed in summary).
* **Complexity:** Low to Medium (SIP DoS is typically low complexity; RCE on ASICs is typically high complexity).
* **Attack Vector:** Network (Remote).
## Impact
* **Confidentiality:** High (Potential for full system compromise on Nexus devices).
* **Integrity:** High (System state can be modified via RCE).
* **Availability:** High (Device reloads and service interruptions for both switches and phones).
## Remediation
### Patches
Cisco recommends upgrading to the following fixed releases:
* **Desk Phone 9800 / Video Phone 8875:** Update to **5.0(1)** or later.
* **IP Phone 7800/8800:** Update to **14.4(1)SR3** or later.
* **IP Phone 8845/8865:** Update to **14.4(1)SR4** or later.
* **Wireless IP Phone 8821:** Update to **11.0(6)SR8** or later.
* **Nexus 9000/IOS XR:** Consult the specific Cisco Software Checker for version-specific migration paths.
### Workarounds
* **Traffic Filtering:** Implement Access Control Lists (ACLs) to permit SIP traffic only from trusted VoIP controllers (CUCM).
* **Control Plane Policing (CoPP):** On Nexus devices, ensure CoPP is configured to drop malformed or unexpected traffic directed at the supervisor engine.
## Detection
* **Indicators of Compromise:** Unexpected reloads of IP phones; unusual CPU spikes on Nexus Silicon One modules; logs indicating SIP processing errors.
* **Detection Methods:** Use `show version` on phones to verify software levels. Monitor syslog for `%CP-3-SIP_ERROR` or similar hardware-level exceptions on Nexus switches.
## References
* Cisco Nexus 9000 RCE: hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
* Cisco IOS XR Hardening: hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
* Cisco IP Phone DoS: hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv
* General Cisco Advisories: hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/publicationListing[.]x