Critical

Cisco, Nexus 9000, CVE-2026-20212, Network Security, Remote Code Execution, IOS XR

Cisco Nexus 9000 CVE-2026-20212: Unauth Root RCE

Cisco Nexus 9000 CVE-2026-20212 is a CVSS 9.8 unauthenticated remote code execution flaw giving root on Silicon One switches via exposed ports 43210 and 43211.

Cisco Nexus 9000 CVE-2026-20212 is a critical, CVSS 9.8 vulnerability that lets an unauthenticated remote attacker run code as root on 10 Silicon One-based Nexus 9000 Series switches. The flaw exists because the switch binds a service to an unrestricted address, leaving TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance. Any attacker who can reach the switch on either port can connect directly, and crafted input sent to that service is then executed with root privileges. A failed attempt can also crash the S1HAL process and reload the device.

Cisco disclosed the bug on September 2, 2026 and said it is not aware of any malicious use so far. There is no simple fixed-release table: Cisco has not published one and instead directs customers to its Software Checker, listing 45 NX-OS releases from 10.3(1) through 10.6(3s) as affected per the CVE Program record. As stopgaps, Cisco recommends an infrastructure access control list (iACL) that blocks the two ports and a temporary Live Protect shield until a fixed image is confirmed for a given platform.

The same disclosure cycle shipped an IOS XR hardening release bundling seven umbrella CVEs, two of them rated 9.8, with no workaround for any IOS XR version. Under Cisco's twice-monthly risk-based model, each umbrella CVE covers one weakness category and is scored at its most severe defect, so a single identifier like CVE-2026-20274 can represent a cluster of memory-safety fixes rather than one bug.

Which Nexus 9000 switches are affected by CVE-2026-20212?

Only the 10 Silicon One-based Nexus 9000 models are affected, identified by product ID against the output of the show module command. Other Nexus 9000 switches, Nexus 9000 fabric switches running in Application Centric Infrastructure (ACI) mode, and the entire Nexus 3000 and 7000 lines are not affected. Because Cisco published no clean fixed-version list, defenders must run the Software Checker per platform rather than assume a single target release.

Why does an unexploited 9.8 still demand emergency action?

Because the preconditions are trivial and the payoff is total. The attack needs no credentials and no user interaction, the vulnerable ports sit in the default routing instance, and success yields root on a core switch that sees and steers traffic for everything behind it. EPSS still sits near the 43rd percentile and the CVE is not yet in CISA KEV, which reflects the absence of public exploitation, not the absence of risk. A network fabric device with unauthenticated root exposure is exactly the kind of target that goes from quiet to weaponized the moment a proof-of-concept circulates.

Detail

Value

CVE

CVE-2026-20212

CVSS 3.1

9.8 Critical (AV:N/AC:L/PR:N/UI:N)

Weakness

CWE-1327 exposed service binding

Exposure

TCP 43210 and 43211 in default L3 VRF

Affected

10 Silicon One Nexus 9000 models; 45 NX-OS releases 10.3(1)-10.6(3s)

Exploited

Not as of September 2, 2026 disclosure

Stopgap

iACL blocking both ports; Live Protect shield

Our read

A network switch that can be rooted by anyone who can reach two TCP ports is the definition of a choke point worth verifying, not assuming. The missing fixed-release table makes this harder than a normal patch: teams have to enumerate their actual Nexus 9000 PIDs and NX-OS trains, confirm reachability of 43210 and 43211, and apply the iACL now rather than wait on a per-platform image. The lesson that keeps repeating is that management and control-plane services should never be reachable from untrusted segments in the first place. Continuous verification means proving those ports are unreachable from where an attacker would sit, before someone else proves they are not.

Reporting by The Hacker News; CVSS and CWE per NVD and the CVE Program record; affected-platform detail per Cisco's Nexus 9000 advisory. Sources linked above.

Related: What is privilege escalation? and How to prioritize vulnerabilities.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.