Zero Day Room
Live
Vulnerabilities

Critical Cisco Nexus 9000 Flaw Allows Remote Root Code

Cisco patches a critical 9.8-rated vulnerability (CVE-2026-20212) in ten Nexus 9000 switch models, allowing unauthenticated remote attackers to run code as

Cisco patches a critical 9.8-rated vulnerability (CVE-2026-20212) in ten Nexus 9000 switch models, allowing...

Cisco has patched a critical security flaw in its Nexus 9000 series switches that permits unauthenticated remote attackers to execute arbitrary code with root privileges. The vulnerability, tracked as CVE-2026-20212 and carrying a maximum CVSS score of 9.8, affects ten specific switch models based on Cisco's Silicon One architecture.

The flaw stems from a service binding to an unrestricted IP address, leaving TCP ports 43210 and 43211 exposed in the default Layer 3 virtual routing and forwarding instance. According to Cisco's advisory, an attacker who can reach a switch's address on either port can connect directly to the vulnerable service. Sending crafted input to this service leads to code execution with the highest system privileges. A failed exploitation attempt can also crash the S1HAL process and force the device to reload.

Cisco stated it is not aware of any malicious use of this flaw as of its disclosure date, September 2. The company has not published a fixed-release table, directing customers instead to its Software Checker tool for patch guidance. Temporary mitigations include implementing an infrastructure access control list to block the two exposed ports and applying a temporary Live Protect shield.

Affected Products and Mitigations

The vulnerability is limited to ten specific Nexus 9000 switch product identifiers. Other Nexus 9000 models, those running in ACI mode, and the Nexus 3000 and 7000 product lines are not affected.

Affected Product Identifier (PID)
N9324C-SE1U (Nexus Smart Switch)
N9348Y2C6D-SE1U (Nexus Smart Switch)
N9364E-SG2-O
N9364E-SG2-Q
N9396T12C-SE1
N9348Y12C-SE1
N9396Y12C-SE1
N9336C-SE1
N9K-C9804
N9K-C9808

Cisco confirms that 45 NX-OS software releases, from version 10.3(1) through 10.6(3s), are vulnerable. The primary remediation is to upgrade to a release identified by Cisco's Software Checker. The operational mode for the temporary Live Protect shield transitions to "N/A"upon upgrade to NX-OS 10.6(4) or higher."the window between disclosure and exploitation has effectively closed."

For IOS XR, including the XR7 (LNT) platforms like the Cisco 8000 Series, the fix involves upgrading to a supported release and then applying specific software maintenance updates (SMUs). Cisco states there may be approximately 16 SMUs available for each release. Future releases 26.2.2 and 26.3.1 will be the first fixed versions requiring no additional SMUs. Customers running a release not listed in the advisory are instructed to open a Technical Assistance Center case.

Available Software Maintenance Updates

SMUs are currently available for the following IOS XR releases. Four additional releases are listed as awaiting future SMUs.

Release
6.9.2
7.3.2
7.9.2
7.9.21
7.10.2
7.11.2
7.11.21
24.2.2
24.2.21
24.4.2
25.2.21
25.4.1
25.4.2
26.1.2
26.2.1

The advisory provides a detailed list of SMU identifiers by functional area, such as BGP, cryptography, and routing protocols. For instance, the SMU CSCwv19790 applies to all XR7 (LNT) platforms across all releases, while CSCwu14807 addresses a BGP vulnerability. The Hacker News cross-checked the advisory on September 3, finding that of 111 affected IOS XR releases, 14 have SMUs available now, four are awaiting them, and 93 require an upgrade before a fix can be applied.

This September 2 disclosure is the third scheduled hardening release in a 30-day period. The same day's advisories also included fixes for two S/MIME decryption flaws in Secure Email gateways and a denial-of-service bug in several Cisco phone models. The development follows a report from cybersecurity firm Sygnia six days earlier detailing activity by the China-nexus threat actor Fire Ant, which used purpose-built implants on IOS XR routers to hide network tunnels and capture traffic. Sygnia's report did not link the campaign to any specific Cisco vulnerability.

Topics

#Cisco

Related coverage

More from Vulnerabilities