Cisco fixes CVE-2026-20212 in Nexus 9000
Cisco patched a critical flaw in Silicon One-based Nexus 9000 switches that allows unauthenticated remote code execution as root.
Cisco fixed CVE-2026-20212, a critical flaw in Silicon One-based Nexus 9000 switches that allows unauthenticated remote code execution as root. The vulnerability exposes TCP ports 43210 and 43211 through the default Layer 3 VRF, and the vendor said it had no knowledge of exploitation when it issued its advisory.
Cisco disclosed and patched CVE-2026-20212, a critical vulnerability in Silicon One-based Nexus 9000 switches that allows remote code execution with root privileges without authentication. The issue affects specific models in the series and exposes TCP ports 43210 and 43211 through the default Layer 3 VRF, according to technical notices and Cisco's official advisory.
What did Cisco publish about the flaw?
Cisco published the official advisory cisco-sa-n9k-s1-rce-EH8dEtr on September 2, 2026, and rated CVE-2026-20212 as critical with a CVSS score of 9.8. The notice includes fixes for affected devices and also mentions temporary mitigations for environments where immediate patching is not possible.
Cisco's own documentation, as reflected in technical media reports and vulnerability databases, places the flaw in the network service exposure of the Nexus 9000 with Silicon One ASICs. Feedly summarizes it with the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which indicates remote exploitation by an unauthenticated attacker, with no user interaction, and high impact to confidentiality, integrity, and availability.
Which devices are affected?
The scope published by technical outlets is limited to specific Cisco Nexus 9000 models with Silicon One ASICs. The listed devices include N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808.
Cisco clarified, according to several advisory summaries, that other products such as Nexus 3000, Nexus 7000, MDS 9000, and Nexus 9000 fabric switches running in ACI mode are not affected by CVE-2026-20212. Specialized media also report that no other vulnerable products were known outside that list at the time of publication.
What is the technical cause of the problem?
Independent analyses explain that TCP ports 43210 and 43211 are bound to a single IP address without restrictions inside the default L3 VRF. That makes them reachable from any source that can route to the switch, beyond the intended management infrastructure.
The CWE-1327 classification tied to CVE-2026-20212 points to a design flaw in the way network services are exposed. In practice, the issue leaves two TCP ports accessible from untrusted networks in the default VRF, which enables remote code execution with root privileges.
Researchers also warned that the vulnerability can cause the S1HAL process to crash, with the possibility of forcing a device reload under certain conditions. Technical outlets further note that the impact reaches data center fabrics built for AI and high performance computing, where these switches serve as part of the architecture's backbone.
What did Traficom say?
Traficom included CVE-2026-20212 in its Cisco vulnerability bulletin and said the corrective update had already been released. The agency also said that, at the time of its notice, the vendor was not aware of any exploitation of the flaw.
As a mitigation measure, Cisco recommends applying the available patches and, in the meantime, using iACLs to block inbound traffic to TCP ports 43210 and 43211 in environments where immediate updating is not possible.
Sources
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Attackers Execute Code as Rootcyberpress.org· CyberPress
- CVE-2026-20212 - Exploits & Severityfeedly.com· Feedly CVE index
- Cisco warnt vor kritischer Nexus-9000-Schwachstelle und liefert IOS-XR-Hardeningit-boltwise.de· IT-Boltwise
- Cisco Nexus 9000 Silicon One RCE Exposes AI Data Center Fabric to Root Compromisetech.yahoo.com· Yahoo Tech
- Cisco Nexus 9000: falla RCE root e nuove vulnerabilità in IOS XR e Secure Emailmatricedigitale.it· Matrice Digitale
- SonicWall Zero-Days Under Active Attack, 153M Driver's License ...rodtrent.substack.com· Rod Trent (Substack)
- Cisco Fixed Critical RCE in Nexus 9000 Series Switchessecurityaffairs.com· Security Affairs
- CVE-2026-20212tenable.com· Tenable
- CVE-2026-20212: The Cisco Nexus 9000 Bug That Turns a ...xhack.io· XHack
- Cisco-tuotteissa kriittisiä haavoittuvuuksia | Traficomkyberturvallisuuskeskus.fi· Traficom
- Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilitiessecurityweek.com· SecurityWeek



