Home · Wiki · Vulnerabilities & CVEs
type: vulnerability · created: 2026-09-04 · updated: 2026-09-04 · tags: · confidence: high · severity: critical · affected_sectors: · au_impact: true

CVE-2026-20212

CVE-2026-20212 is a pre-authentication remote code execution vulnerability affecting ten Silicon One–based Cisco Nexus 9000 Series switches. It has a CVSS base score of 9.8 (critical).

The root cause is the affected software binding to an unrestricted IP address, which leaves TCP ports 43210 and 43211 reachable in the default Layer 3 VRF. A remote, unauthenticated attacker who can reach the switch's management address can send crafted input to these ports. This input is executed with root privileges, or alternatively can crash the S1HAL process and force a reload of the device, resulting in a denial of service.

Disclosure and patching

  • The flaw was disclosed by Cisco on 2 September 2026.
  • There is no workaround for any version of IOS XR that addresses the vulnerability.
  • Organisations should apply the fixed software release issued for the affected Nexus 9000 platforms as soon as practicable, prioritising Internet-facing or otherwise reachable devices.

The affected ten Nexus 9000 switch platforms are those based on the Silicon One ASIC, and the fix ships alongside a broader IOS XR hardening release covering multiple related CVEs.