Skip to content

Warning: Critical Remote Code Execution vulnerability in NX-OS, Patch Immediately!

Ccb.Belgium.Be September 3, 2026

Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches containing Silicon One ASIC

Denial of Service (DoS)

Remote Code Execution (RCE)

CVE/CVSS: CVE-2026-20212: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Cisco Nexus 9000 Series Switches are data-center switches used to provide high-throughput network connectivity and segmentation. CVE-2026-20212 affects Cisco Nexus 9000 Series Switches if they include a Silicon One ASIC. The Cisco advisory contains a listing of affected models.

CVE-2026-20212 is a vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches which could allow an unauthenticated, remote attacker to execute code with root privileges. Historic post-exploitation activity of similar vulnerabilities included further network pivoting, the deployment of persistent implants, ...

At the time of publication, Cisco PSIRT had no knowledge of any public disclosure or malicious exploitation of this vulnerability.

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

The Centre for Cybersecurity Belgium strongly recommends hardening the device in accordance with the vendor’s security guidelines. For this specific vulnerability Cisco recommends to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. Please refer to the associated Cisco advisory for additional information.

The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.

The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion. The CCB provides a document outlining recommendations for network device logging.

In case of an intrusion, you can report an incident via .

While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.

CCB network device logging recommendations