Cisco Fixed Critical RCE in Nexus 9000 Series Switches
Brief
Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution.
Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9. 8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges.
Cisco’s Technical Assistance Center (TAC) discovered the flaw while investigating a customer support case.
The flaw exists because TCP ports 43210 and 43211 are exposed through the default Layer 3 VRF. An attacker could connect remotely and send specially crafted data that gets executed with root privileges. The attack could also crash the S1HAL process, potentially forcing the affected device to reload.
