ZeroHour
Product

Cisco 8000 Series

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco patches critical CVE-2026-20212 (CVSS 9.8) in Nexus 9000 switches allowing unauthenticated remote root code execution, plus IOS XR hardening release.

Cisco released fixes for CVE-2026-20212 (CVSS 9.8), a flaw in 10 Silicon One-based Nexus 9000 switch models that binds a service to an unrestricted IP, leaving TCP ports 43210/43211 reachable in the default Layer 3 VRF and allowing unauthenticated remote attackers to execute code as root; exploitation attempts can also crash the S1HAL process. 45 NX-OS releases (10.3(1) through 10.6(3s)) are affected, with mitigations including infrastructure ACLs, the Live Protect shield lp00031, and fixed releases identified via Cisco's Software Checker. Cisco simultaneously issued an IOS XR hardening release bundling 7 umbrella CVEs, two rated 9.8 (CVE-2026-20274 for memory-safety bugs and CVE-2026-20279 for access-control bugs), affecting all releases with SMUs available for 14 releases and upgrades required for 93 of 111 listed releases. No malicious exploitation was reported as of the September 2 disclosure.

Related CVEs

  • Critical Improper Access Control in Cisco IOS XR Software
    CVE-2026-20279 covers one or more improper access control flaws (CWE-284) in Cisco IOS XR Software, discovered by Cisco's own engineering team during an internal security review and addressed in a bundled software hardening release. According to the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaws are remotely exploitable over the network with no authentication and no user interaction, and the 9.8 critical score reflects high impact to confidentiality, integrity, and availability, though the specific attack path is not detailed in the available data. A successful unauthenticated remote attacker would gain high-impact access to the affected device per the CVSS scoring, on networks running IOS XR, which is deployed primarily on Cisco's service-provider routing platforms. The fix was rolled into Cisco's coordinated September 2, 2026 advisory bundle, in which the IOS XR team consolidated patches for multiple internally discovered issues into a single update release, published alongside other Cisco fixes (including a separate critical Nexus 9000 issue). No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known; EPSS estimates the 30-day exploitation probability at roughly 0.3%.
    · Cisco IOS XR Softwarelarge
  • Critical Improper Resource Control Flaws in Cisco IOS XR Software
    CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days.
    · Cisco IOS XR Softwarelarge
  • Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration
    CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.
    · Cisco Nexus 9000 Series Switches with Silicon One integrationlarge
  • Improper Neutralization Flaws in Cisco IOS XR Software (CWE-707)
    CVE-2026-20278 covers a set of improper neutralization weaknesses (CWE-707) in Cisco IOS XR Software that Cisco's engineering team discovered during an internal security review and addressed in dedicated software hardening releases. The issues are remotely exploitable over the network by an attacker who holds valid low-privileged credentials on the device (CVSS vector AV:N/AC:L/PR:L/UI:N), with no user interaction required. Successful exploitation yields high impact to the confidentiality, integrity, and availability of the affected component, consistent with broad compromise of the impacted device functionality. Any operator running the affected IOS XR releases is in scope; IOS XR is Cisco's carrier-grade router operating system, though specific affected and fixed version ranges are not provided in the available data. There is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so it is not currently known to be exploited in the wild.
    · Cisco IOS XR Softwarelarge
  • Improper Exception-Condition Handling (CWE-703) in Cisco IOS XR Software
    CVE-2026-20280 is a group of multiple internally discovered flaws in Cisco IOS XR Software, Cisco's operating system for carrier-grade routing platforms, all involving improper checking or handling of exceptional conditions (CWE-703). They were found by the IOS XR engineering team during a comprehensive internal security review and are addressed via software hardening releases announced in Cisco's September 2, 2026 advisory batch. Per the CVSS vector, an attacker with valid low-privileged credentials can trigger the flaw over the network without user interaction (AV:N/AC:L/PR:L/UI:N) and gain high-impact effects on the device's confidentiality, integrity, and availability (C:H/I:H/A:H); the exact impact mechanism is not detailed in the available data. Organizations operating IOS XR-based routing infrastructure — typically service providers, telecom operators, and large enterprises — are affected. There is no evidence of exploitation in the wild, no known public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.3% (19th percentile); the related Nexus 9000 critical RCE headline refers to a separate advisory published in the same batch, not this CVE.
    · Cisco IOS XR Softwarelarge
  • Incorrect Calculation Vulnerabilities in Cisco IOS XR Software
    CVE-2026-20275 tracks multiple internally discovered incorrect-calculation issues (CWE-682) in Cisco IOS XR Software, found during Cisco's internal security review and addressed through dedicated software hardening releases. According to the CVSS 3.1 vector (AV:A/AC:L/PR:N/UI:N), an unauthenticated attacker positioned on an adjacent network segment could trigger the flaw with no user interaction or privileges required. Successful exploitation carries high-impact consequences for confidentiality, integrity, and availability (CVSS 8.8, High), though the advisory summary does not detail the precise mechanism or the exact attacker gain. Any deployment running Cisco IOS XR Software is potentially affected; defenders should consult Cisco's September 2, 2026 advisory publication for exact affected releases and fixed versions, which are not specified in the available data. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
    · Cisco IOS XR Softwarelarge
  • Unauthenticated Remote DoS Flaws in Cisco IOS XR Software
    CVE-2026-20276 covers a set of internally discovered vulnerabilities in Cisco IOS XR Software caused by insufficient control flow management (CWE-691), which Cisco addressed through software hardening releases following a comprehensive internal security review. The flaws are exploitable over the network by unauthenticated attackers with no user interaction or privileges required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). With no confidentiality or integrity impact but a high availability impact and changed scope, successful exploitation most likely causes a denial-of-service condition such as a device crash or process restart. Any organization running Cisco IOS XR — typically service providers and large enterprises operating carrier-grade routing infrastructure — is potentially affected, although the available data does not specify affected or fixed versions. There is no known exploitation in the wild, no public proof-of-concept, and EPSS assigns only a 0.3% 30-day exploitation probability, making this a schedule-patch rather than an emergency.
    · Cisco IOS XR Softwarelarge
  • Protection Mechanism Failures in Cisco IOS XR Software (CVSS 8.2)
    CVE-2026-20277 covers a group of protection mechanism failure vulnerabilities (CWE-693) in Cisco IOS XR Software that Cisco's engineering team discovered during a comprehensive internal security review and addressed in dedicated software hardening releases. The flaws are remotely exploitable over the network without credentials or user interaction, according to the CVSS vector (AV:N/AC:L/PR:N/UI:N). A successful attacker would gain a high availability impact and a low integrity impact, meaning the ability to disrupt or partially alter the behavior of the device without direct disclosure of its data (confidentiality impact is rated none). Any organization running affected IOS XR releases on Cisco's carrier-grade routing platforms is in scope, though exact affected version ranges are not specified in the available data. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.
    · Cisco IOS XR Softwarelarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.