ZeroHour
The Hacker Newspublished ()ingested [email protected] (The Hacker News)

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

AI summary · glm-5.3-flash

Cisco patches critical CVE-2026-20212 (CVSS 9.8) in Nexus 9000 switches allowing unauthenticated remote root code execution, plus IOS XR hardening release.

Cisco released fixes for CVE-2026-20212 (CVSS 9.8), a flaw in 10 Silicon One-based Nexus 9000 switch models that binds a service to an unrestricted IP, leaving TCP ports 43210/43211 reachable in the default Layer 3 VRF and allowing unauthenticated remote attackers to execute code as root; exploitation attempts can also crash the S1HAL process. 45 NX-OS releases (10.3(1) through 10.6(3s)) are affected, with mitigations including infrastructure ACLs, the Live Protect shield lp00031, and fixed releases identified via Cisco's Software Checker. Cisco simultaneously issued an IOS XR hardening release bundling 7 umbrella CVEs, two rated 9.8 (CVE-2026-20274 for memory-safety bugs and CVE-2026-20279 for access-control bugs), affecting all releases with SMUs available for 14 releases and upgrades required for 93 of 111 listed releases. No malicious exploitation was reported as of the September 2 disclosure.

  • CVE-2026-20212 (CVSS 9.8) allows unauthenticated remote root code execution on Nexus 9000 switches.
  • Flaw exposes TCP ports 43210/43211 in default L3 VRF; attempts can crash S1HAL process.
  • 45 NX-OS releases affected from 10.3(1) to 10.6(3s); mitigations include iACL and Live Protect shield.
  • IOS XR hardening release bundles 7 umbrella CVEs, two rated 9.8 (CVE-2026-20274, CVE-2026-20279).
  • SMUs available for 14 of 111 affected IOS XR releases; no exploitation reported at disclosure.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20212
Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration

CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.

Do: Inventory your Nexus 9000 fleet to identify Silicon One–integrated models and test whether TCP ports 43210/43211 are reachable in the default L3 VRF (e.g., nmap the management/default VRF or review interface and control-plane ACLs). Upgrade to the fixed software release listed in Cisco's advisory published September 2, 2026. As an interim mitigation, restrict access to ports 43210 and 43211 via ACLs and monitor for S1HAL process crashes or unexpected device reloads.

9.8<1%
  • Cisco Nexus 9000 Series Switches with Silicon One integration
large≈ tens of thousands of deployed switches plausibly in the affected subset (Silicon One–based Nexus 9000 models), of which likely only a few thousand have TCP…
CVE-2026-20274
Critical Improper Resource Control Flaws in Cisco IOS XR Software

CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days.

Do: Upgrade affected IOS XR devices to the security/hardening release bundled in Cisco's September 2, 2026 advisory batch, checking that advisory for the exact fixed release for your version train. Until patching is complete, restrict network reachability of IOS XR management and control planes to trusted operators, since the flaws require no authentication or user interaction. Organizations also running Cisco Nexus 9000 switching should review the separate, same-day NX-OS advisory for the unauthenticated root RCE reported in related coverage.

9.8
group max
<1%
  • Cisco IOS XR Software
large≈10^5 (on the order of ~100,000) internet-exposed IOS XR devices per public scan counts; total deployed fleet, including carrier-internal routers, is larger…
Full article1,258 words · extracted from thehackernews.com · click to collapse

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.

The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance.

An attacker who can reach a switch's address on either port can connect directly to the service. Crafted input sent to that service is then executed as code with root privileges. An exploitation attempt can also crash the S1HAL process and reload the device.

Cisco said it's not aware of any malicious use of the flaw as of its September 2 disclosure. It has published no fixed-release table and directs customers to its Software Checker, with an infrastructure access control list (iACL) blocking the two ports and a temporary Live Protect shield as stopgaps.

Cisco tells IOS XR customers, including those on IOS XR7 (LNT), to upgrade to a release that includes software maintenance updates (SMUs), then apply them.

"At the same time, the window between disclosure and exploitation has effectively closed," Russ Smoak, vice president of information security at Cisco, said in a June blog post announcing the twice-monthly disclosure model that groups internally found bugs into umbrella CVEs.

Cisco lists the following affected product identifiers (PIDs) in its Nexus 9000 advisory, checkable against the output of the show module command -

  • N9324C-SE1U (Nexus Smart Switch)
  • N9348Y2C6D-SE1U (Nexus Smart Switch)
  • N9364E-SG2-O
  • N9364E-SG2-Q
  • N9396T12C-SE1
  • N9348Y12C-SE1
  • N9396Y12C-SE1
  • N9336C-SE1
  • N9K-C9804
  • N9K-C9808

Other Nexus 9000 models, Nexus 9000 fabric switches running in Application Centric Infrastructure (ACI) mode, and the Nexus 3000 and 7000 lines are unaffected.

The Hacker News confirmed via the CVE Program's record on September 3 that Cisco lists 45 NX-OS releases, from 10.3(1) through 10.6(3s), as affected, a range the advisory itself leaves to the Software Checker.

Until a fixed release is confirmed, Cisco offers the following -

  • Upgrade to the release named by Cisco's Software Checker; the shield's release notes state that its operational mode transitions to N/A on upgrade to NX-OS 10.6(4) or higher.
  • iACL permitting only required management and control-plane traffic, or explicitly denying TCP packets to a locally configured IP address on destination port 43210 or 43211, proven in a test environment.
  • Live Protect shield lp00031, a temporary mitigation described in Cisco's Live Protect documentation, supported only on NX-OS 10.6(3) and, via a second shield package, on 10.6(3s) for the two Smart Switches; it's unsupported on the Nexus 9804 and 9808 and needs SSH, Telnet, or NX-API access.

IOS XR Hardening Release Reaches Every Version

The IOS XR release assigns one CVE to each Common Weakness Enumeration (CWE) bucket of fixed bugs and scores it at the most severe defect in that bucket, per the rules in its risk-based disclosure FAQ.

CVE-2026-20274, which covers memory-safety and resource-lifetime bugs, and CVE-2026-20279, which covers access-control bugs including missing authentication for critical functions and improper certificate validation, each carry a 9.8 ceiling in the record for CVE-2026-20274 and that for CVE-2026-20279.

The remaining five, CVE-2026-20275 through 20278 and CVE-2026-20280, top out between 8.2 and 8.8.

The vulnerabilities affect all releases regardless of device configuration, the IOS XR hardening advisory said.

The XR7 (LNT) platforms, which include the Cisco 8000 Series, NCS 1010, NCS 540L, and NCS 5700 Series, have a dedicated SMU that applies across all releases.

Cisco said there may be "approximately 16 SMUs available for each release," that future releases 26.2.2 and 26.3.1 will be the first fixed releases needing no SMUs, and that customers running a release outside its table should open a Technical Assistance Center (TAC) case.

SMUs are available for the following releases -

  • 6.9.2
  • 7.3.2
  • 7.9.2
  • 7.9.21
  • 7.10.2
  • 7.11.2
  • 7.11.21
  • 24.2.2
  • 24.2.21
  • 24.4.2
  • 25.2.21
  • 25.4.1
  • 25.4.2
  • 26.1.2
  • 26.2.1

SMUs are listed as future releases for 24.1.2, 24.3.2, 25.1.2, and 25.2.2.

The advisory lists the following SMU identifiers by functional area -

  • All XR7 (LNT) platforms - CSCwv19790, on all releases.
  • BGP - CSCwu14807; the 7.10 and earlier trains and 26.2.1 are not vulnerable.
  • crypto-ike - CSCwv19170.
  • gRPC - CSCwt41683.
  • IP-SLA - CSCwv19173.
  • IS-IS - CSCwv45645 and CSCwv19171; on 25.4.2, and on 25.4.1 for the NCS1001, NCS1004, and NCS1010, CSCwu13271 and CSCwv19171; 26.1.2 and 26.2.1 are not vulnerable.
  • MPLS and MPLS-TE - CSCwv40753 and CSCwu14825; on 24.2.21 for 64-bit ARM Cisco 8000 Series routers, CSCwv19181 and CSCwu14825.
  • Multicast - CSCwv19180 and CSCwu08799.
  • OSPF - CSCwv40741 and CSCwv19171; on 24.2.21 for 64-bit ARM Cisco 8000 Series routers, CSCwv19174 and CSCwv19171.
  • Segment routing, IPv6 only - CSCwu13268; CSCwv56312 on 7.11.21, 24.2.21, 25.2.21, and 25.4.1, on 7.9.21 for 64-bit ASR 9000 Series routers, and on 7.3.2 for the NCS1002; 26.1.2 and 26.2.1 are not vulnerable.
  • Segment routing, IPv4 only or IPv4 and IPv6 - CSCwv38342; on 24.2.21 for 64-bit ARM Cisco 8000 Series routers, CSCwv19178.
  • TCP Authentication Option - CSCwv36143; on 24.2.21 for 64-bit ARM Cisco 8000 Series routers, CSCwu14817; on 6.9.2 for 32-bit ASR 9000 Series routers, CSCww16661.
  • Zero Touch Provisioning (ZTP) - CSCwu36622; 26.2.1 is not vulnerable.

CSCwv19171 applies to both IS-IS and OSPF, Cisco noted.

The Hacker News cross-checked the seven CVE records against the advisory on September 3 and found that, of the 111 IOS XR releases Cisco lists as affected, 14 have SMUs available today, four are awaiting SMUs, and 93 must first be upgraded before a fix can be applied.

The September 2 drop is the third scheduled hardening release in 30 days, following the first hardening drop on August 5, which delivered the IOS XE hardening release and a Catalyst SD-WAN release, and two CVSS 10.0 releases for Crosswork and Secure Workload two weeks later.

Separately, two publicly disclosed Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption flaws in Secure Email, CVE-2026-20354 and CVE-2026-20355 (CVSS scores: 5.9), allow a machine-in-the-middle attacker to recover plaintext from mail passing between gateways running AsyncOS 16.5.0 or earlier with S/MIME configured, Cisco said in the Secure Email advisory. Fixed releases for that pair are stated only in the bug records.

The same day's advisories also fixed a phone denial-of-service bug, CVE-2026-20281 (CVSS score: 7.5), in Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 devices registered to Unified Communications Manager with Web Access enabled, a setting that's off by default. Fixes arrive in SIP Software 5.0(1), 14.4(1)SR3, 14.4(1)SR4, or 11.0(6)SR8 depending on the model.

The development comes six days after Sygnia said the China-nexus threat actor Fire Ant, first documented in 2025, ran purpose-built implants on IOS XR routers that suppressed syslog delivery, filtered show command output, and supported a hidden Generic Routing Encapsulation (GRE) tunnel.

The actor also captured packets from routers, uploaded them to external FTP servers, and made connection attempts and port scans against connected systems associated with critical infrastructure.

The investigation began with a tunnel interface active on a router with no running configuration or commit history to explain it, which, Sygnia said in its Fire Ant report, suggested the device's operational state "could no longer be trusted to match the configuration and audit records."

Sygnia did not identify how the actor first gained access to the routers or name any vulnerability.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html