Skip to content
RCE Vulnerability Discovered in Cisco Nexus 9000 Switches

RCE Vulnerability Discovered in Cisco Nexus 9000 Switches

First seen 7 Oct 2026, 15:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 17:29 UTC
  • •CVE-2026-20212 allows unauthenticated RCE on Cisco Nexus 9000 switches.
  • •The vulnerability affects multiple product identifiers and is rated CVSS 9.8.
  • •A fix is available in NX-OS 10.6(4) and later; workarounds are also provided.

A vulnerability, CVE-2026-20212 (CVSS 9.8), has been identified in Cisco Nexus 9000 Series switches, allowing unauthenticated remote code execution through default TCP ports 43210 and 43211. Disclosed on September 2, 2026, during a TAC support case, the flaw affects specific product identifiers across Smart Switches and the Nexus 9800 chassis line. The vulnerability arises from the S1HAL process binding to an unrestricted IP address, making it exploitable without authentication. Cisco has released a fix in NX-OS version 10.6(4) and later, and provided a workaround to deny traffic to the vulnerable ports. This is the third CVE reported in Cisco's enterprise infrastructure in recent weeks, highlighting a trend of trust-through-defaults failures. Cisco is not aware of any as of the publication date.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-02
CVE-2026-20212 disclosed
Cisco announced a critical RCE vulnerability affecting Nexus 9000 switches, found during TAC support case resolution.
Tech.Yahoo
2026-09-16
CVE-2026-76460 added to CISA KEV
CISA added CVE-2026-76460, a critical vulnerability in Cisco ISE, to its Known Exploited Vulnerabilities catalog.
Tech.Yahoo
2026-09-30
CVE-2026-76504 added to CISA KEV
CISA listed CVE-2026-76504, a critical vulnerability in Cisco SD-WAN Manager, as actively exploited.
Tech.Yahoo

More articles in this cluster (2)

Following this threat?

Track Cisco and CVE-2026-20212 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Nexus 9000 models are affected?
The vulnerability affects ten specific product identifiers, including N9324C-SE1U and N9348Y12C-SE1.
Is there a patch available?
Yes, a fix is available in NX-OS version 10.6(4) and later.
What should I do if I can't patch immediately?
Implement the provided workaround to deny TCP traffic to ports 43210 and 43211.