logo

Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Execute Code as Root Without Authentication

ID: fada1876-9e04-58d0-8f90-85ead030f0bd

STIX ID: report--fada1876-9e04-58d0-8f90-85ead030f0bd

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

Author: Divya

...
...

Cisco published a security advisory for CVE-2026-20212, a critical (CVSS 9.8) remote code execution flaw in Nexus 9000 Series switches with Silicon One ASICs that is reachable via TCP ports 43210 and 43211; successful exploitation can yield root code execution and may also crash the S1HAL process causing reboots/DoS. Cisco lists specific affected models, recommends upgrading to fixed NX-OS releases, using iACLs to block the ports as an interim measure and deploying a Live Protect shield; no known public exploitation was reported as of the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.