Critical RCE Vulnerability in Cisco Nexus 9000 Switches Disclosed

Critical RCE Vulnerability in Cisco Nexus 9000 Switches Disclosed

First seen 3 Sep 2026, 14:51 UTC Sec.Cloudapps.CiscoForkast.NewsEsecurityplanetCcb.Belgium.BeThehackernews+6 70.5

Article Content

Browse articles
ThreatCluster

On September 2, 2026, Cisco disclosed a critical vulnerability (CVE-2026-20212) affecting its Nexus 9000 Series Switches equipped with Silicon One ASICs. This flaw allows unauthenticated remote attackers to execute code with root privileges via accessible TCP ports 43210 and 43211 in the default Layer 3 virtual routing and forwarding instance. The vulnerability has a CVSS score of 9.8 and can also crash the S1HAL process, leading to device reloads. Cisco has released patches and recommends implementing infrastructure access control lists (iACLs) to mitigate risks. As of September 3, there are no reports of active exploitation or malicious use of this vulnerability. The affected models include N9324C-SE1U, N9348Y2C6D-SE1U, among others. Organizations are urged to prioritize patching and monitoring for suspicious activity.

Key Points: • CVE-2026-20212 allows unauthenticated remote code execution on Nexus 9000 switches. • Cisco has released patches and recommends immediate remediation for affected models. • No known exploitation has been reported as of September 3, 2026.

Ask AI about this cluster

Timeline

2026-04-01
Public exploit for CVE-2026-48710 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-07-08
CVE-2026-59822 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CVE-2026-20212 published
Cisco disclosed a critical vulnerability in Nexus 9000 switches allowing remote code execution.
Sec.Cloudapps.Cisco
2026-09-02
Patches released
Cisco released patches for the critical vulnerability affecting Nexus 9000 switches.
Thehackernews
2026-09-02
CVE-2026-20274 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CVE-2026-20355 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CVE-2026-20275 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CVE-2026-20279 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CVE-2026-20281 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CVE-2026-20354 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE