CVE-2026-20212: Cisco Nexus 9000 RCE Flaw
Cisco disclosed CVE-2026-20212, a critical unauthenticated remote code execution flaw in the Silicon One integration of Nexus 9000 switches.
Cisco has disclosed CVE-2026-20212, a critical vulnerability in the Silicon One integration used by certain Nexus 9000 switches. The flaw allows an unauthenticated remote attacker to achieve remote code execution. The source excerpt does not state active exploitation or provide patch details.
- CVE-2026-20212 rated critical in Nexus 9000 switches
- Unauthenticated remote code execution scenario
- Flaw resides in Silicon One integration code
- No exploitation reported in the provided text
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20212 | Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days. Do: Inventory your Nexus 9000 fleet to identify Silicon One–integrated models and test whether TCP ports 43210/43211 are reachable in the default L3 VRF (e.g., nmap the management/default VRF or review interface and control-plane ACLs). Upgrade to the fixed software release listed in Cisco's advisory published September 2, 2026. As an interim mitigation, restrict access to ports 43210 and 43211 via ACLs and monitor for S1HAL process crashes or unexpected device reloads. | 9.8 | <1% |
| large≈ tens of thousands of deployed switches plausibly in the affected subset (Silicon One–based Nexus 9000 models), of which likely only a few thousand have TCP… |
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw Cisco has disclosed a critical vulnerability, CVE-2026-20212, in the Silicon One integration used by certain Nexus 9000 switches. The flaw allows an unauthenticated remote attack
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.