Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-04 Β· updated: 2026-09-04 Β· tags: Β· confidence: verified Β· severity: critical Β· affected_sectors: Β· au_impact: true

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Incident note β€” 3 September 2026

On 2 September 2026, Cisco disclosed CVE-2026-20212, a critical pre-authentication remote code execution vulnerability affecting ten Silicon One–based Cisco Nexus 9000 switch platforms, rated CVSS 9.8. The disclosure accompanied an IOS XR hardening release that bundles seven umbrella CVEs, two of which are rated 9.8.

The vulnerability stems from the software binding to an unrestricted IP address, leaving TCP ports 43210 and 43211 reachable in the default Layer 3 VRF. A remote, unauthenticated attacker who can reach the switch address can send crafted input that executes with root privileges, or that crashes the S1HAL process and reloads the device. There is no workaround for any IOS XR version.

Cisco stated that no active exploitation of these flaws had been observed as of the 2 September disclosure. Given the critical severity and the lack of workarounds, affected organisations should still treat the fix as urgent and apply the updated IOS XR release to reachable devices promptly.