Critical Cisco Nexus 9000 Vulnerability Allows Remote Code Execution

Critical Cisco Nexus 9000 Vulnerability Allows Remote Code Execution

First seen 3 Sep 2026, 14:51 UTC Sec.Cloudapps.CiscoForkast.NewsEsecurityplanet 74.0

Article Content

Browse articles
ThreatCluster

On September 2, 2026, Cisco disclosed CVE-2026-20212, a critical vulnerability in Nexus 9000 switches using Silicon One ASICs. This flaw enables unauthenticated remote attackers to execute code with root privileges via TCP ports 43210 and 43211. The vulnerability has a CVSS score of 9.8 and could lead to device outages and denial-of-service conditions. Cisco's advisory indicates that the exposure risk is significant, especially in compromised internal networks. Although no exploitation has been reported yet, organizations are urged to apply patches or implement workarounds immediately. The affected models include N9324C-SE1U, N9348Y2C6D-SE1U, and others listed in the advisory. Cisco recommends using infrastructure access control lists (iACLs) to mitigate risks until patches can be applied. The vulnerability is particularly concerning for AI data centers relying on these switches for high-performance computing.

Key Points: • CVE-2026-20212 allows unauthenticated remote code execution on Cisco Nexus 9000 switches. • The vulnerability has a CVSS score of 9.8 and affects specific models with Silicon One ASICs. • Cisco recommends immediate patching or implementing iACLs to mitigate the risk.

Timeline

2026-04-01
Public exploit for CVE-2026-48710 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-07-08
CVE-2026-59822 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CVE-2026-20212 published
Cisco disclosed a critical vulnerability in Nexus 9000 switches allowing remote code execution.
Sec.Cloudapps.Cisco
2026-09-02
CVE-2026-20212 added to CISA KEV
CISA included CVE-2026-20212 in its Known Exploited Vulnerabilities catalog due to its severity.
Esecurityplanet
2026-09-03
No known exploitation reported
Cisco's advisory states that there has been no malicious use or public announcements regarding CVE-2026-20212.
Forkast.News