Critical Cisco Nexus 9000 Switches Flaw Lets Remote Attackers Run Code
Key Takeaways Cisco has disclosed a critical remote code execution flaw (CVE-2026-20212) in certain Nexus 9000 Series Switches. The vulnerability, rated 9.8 CVSS, allows unauthenticated attackers to...
Key Takeaways
- Cisco has disclosed a critical remote code execution flaw (CVE-2026-20212) in certain Nexus 9000 Series Switches.
- The vulnerability, rated 9.8 CVSS, allows unauthenticated attackers to execute code with root privileges.
- Affected devices are Nexus 9000 models utilizing a Silicon One ASIC.
- Cisco has released patches and recommends immediate software updates.
Critical Flaw Exposes Cisco Nexus 9000 Switches to Remote Root Code Execution
Cisco has announced a severe security vulnerability impacting specific models within its Nexus 9000 Series Switches. This critical flaw, identified as CVE-2026-20212, could enable an attacker to remotely execute arbitrary code with root privileges without needing authentication.
Table Of Content
The vulnerability carries a CVSS score of 9.8 out of 10, underscoring its high severity. It specifically targets Nexus 9000 switches that incorporate a Silicon One ASIC. Cisco’s advisory, cisco-sa-n9k-s1-rce-EH8dEtr, published on September 2, 2026, provides comprehensive details on the issue, which is categorized as CWE-1327.
Cisco indicated that this vulnerability was discovered internally while addressing a Technical Assistance Center (TAC) support case. As of the advisory’s release, the Cisco Product Security Incident Response Team (PSIRT) had no evidence of active exploitation or malicious activities related to this flaw in the wild.
Technical Details of the Vulnerability
The core of the vulnerability lies in the exposure of TCP ports 43210 and 43211. These ports are unexpectedly accessible through the default Layer 3 virtual routing and forwarding (VRF) configuration on affected devices. Attackers can leverage this exposure without requiring any valid credentials.
By establishing a connection to a vulnerable switch and transmitting specially crafted input, an attacker can trigger the execution of this input as code, gaining root-level access to the device. This level of control grants an attacker extensive capabilities over the compromised switch.
Root access could allow an attacker to alter network configurations, monitor traffic, disrupt services, intercept data, or pivot to other systems connected to the network. Cisco also warned that successful exploitation might crash the S1HAL process, potentially forcing the device to reload and causing a network outage.
Affected and Unaffected Products
The vulnerability specifically impacts Cisco Nexus 9000 Series Switches equipped with a Silicon One ASIC. Cisco has provided a list of affected product identifiers, which includes N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808.
Administrators can determine their installed module and product identifier by executing the show module command on their switch. The returned model number should then be cross-referenced with Cisco’s official list of affected products, and the current NX-OS release should be verified for vulnerability using the Cisco Software Checker.
Cisco has confirmed that other Nexus 9000 models not explicitly listed in the advisory are not vulnerable. Additionally, Nexus 9000 Fabric Switches operating in ACI mode are unaffected. A range of other Cisco products, including Nexus 3000 and Nexus 7000 Series Switches, MDS 9000 Series Multilayer Switches, Cisco Firepower appliances, Secure Firewall products, and several UCS Fabric Interconnect platforms, are also not susceptible to this particular flaw.
What You Should Do
- Apply Patches Immediately: Cisco has released software updates to address CVE-2026-20212. Organizations are strongly advised to upgrade to a fixed NX-OS release as soon as possible.
- Implement Infrastructure Access Control Lists (iACLs): Until patching is complete, configure iACLs to restrict network access, permitting only essential management and control-plane traffic to the device.
- Deny Specific TCP Traffic: As an additional temporary mitigation, configure iACLs to explicitly block TCP traffic directed to locally configured switch IP addresses on destination ports 43210 and 43211.
- Utilize Live Protect Shield (Temporary): Cisco has provided a Live Protect shield for interim protection. However, this should be considered a short-term measure until a comprehensive software upgrade is fully deployed.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.