Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root. This vulnerability, tracked as CVE-2026-20212 with a CVSS score of 9.8, involves binding to an unrestricted IP address, leaving TCP ports 43210 and 43211 accessible in the default Layer 3 virtual routing and forwarding (VRF) instance. An attacker who can reach a switch’s address on either port can connect directly to the service, executing crafted input as code with root privileges. Additionally, an exploitation attempt could crash the S1HAL process and reload the device.
As of the September 2 disclosure, Cisco stated it is not aware of any malicious use of the flaw. The company has not published a fixed-release table and is directing customers to its Software Checker for guidance. Cisco recommends that IOS XR customers, including those on IOS XR7 (LNT), upgrade to a release that includes software maintenance updates (SMUs) and apply them. Cisco has also implemented temporary measures, including an infrastructure access control list (iACL) to block the two vulnerable ports and a Live Protect shield.
IOS XR Hardening Release Details
Alongside the Nexus 9000 vulnerability, Cisco has issued an IOS XR hardening release that bundles seven umbrella CVEs, two of which are rated 9.8. This hardening release affects all versions of IOS XR, with vulnerabilities covering memory-safety and access-control issues. Cisco has indicated that there may be approximately 16 SMUs available for each release, with future releases expected to require no SMUs.
For affected product identifiers, Cisco lists several Nexus 9000 models, including N9324C-SE1U and N9348Y2C6D-SE1U, among others. Other Nexus 9000 models and the Nexus 3000 and 7000 lines are unaffected. Cisco’s advisory can be checked against the output of the show module command for verification.
For further details, refer to the advisory published by The Hacker News.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



