INCIBE said Cisco disclosed seven vulnerabilities in IOS XR Software, including two critical and five high-severity flaws, affecting Cisco 8000 Series Routers, NCS 1010, NCS 540L Routers and NCS 5700 Series. The affected surface also covers IOS XR7 and a long list of router features, not just one isolated service.
The issues span control-plane functions such as BGP, IS-IS, OSPF, MPLS, MPLS-TE, gRPC, IP SLA, crypto-ike, TCP Authentication Option, multicast, Segment Routing IPv4/IPv6 and Zero Touch Provisioning. In practice, that means a flaw in a routine routing or provisioning feature can still lead to code execution, denial of service, or unauthorized access, depending on the CVE and platform.
For operators, the exposure sits in shared IOS XR builds across several router families, so the same advisory can touch core and edge gear at once. The reporting does not change the fix path, but it does show why patch review has to be coordinated across the fleet rather than handled as a single-box event.