ZeroHour
Story · 1 source · 1 articlefirst updated ()

Cisco discloses critical IOS XR and Nexus 9000 flaws from internal review, including unauthenticated root RCE CVE-2026-20212 (CVSS 9.8)

What's new: First merged summary. Coverage evolved from Security Affairs (2026-09-03) disclosing only CVE-2026-20212 with workarounds and no fixed NX-OS, to The Register (2026-09-04) revealing the Nexus flaw was part of a larger batch including two critical IOS XR flaws (CVE-2026-20274, CVE-2026-20279, both CVSS 9.8) fixed in new releases, to CSO Online (2026-09-09) adding the full IOS XR picture: seven…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Cisco disclosed a batch of critical flaws found through internal review: CVE-2026-20212 (CVSS 9.8), an unauthenticated remote root code execution bug in the Silicon One integration of Nexus 9000 switches reachable via TCP ports 43210/43211 in the default…

Cisco has disclosed and partially patched a set of critical vulnerabilities discovered through its own review. The most severe, CVE-2026-20212 (CVSS 9.8), resides in the Silicon One integration used by certain Nexus 9000 Series switches and lets unauthenticated remote attackers execute code with root privileges by reaching TCP ports 43210 and 43211, which are exposed through the default Layer 3 VRF. Exploitation can also crash the S1HAL process, forcing device reloads. Only Nexus 9000 switches with Silicon One ASICs are affected; ACI mode and Nexus 3000/7000 are unaffected. The Register reports the flaw affects ten Nexus 9000 models. At disclosure, no software fix was available: mitigations include infrastructure ACLs (iACLs) or blocking traffic to ports 43210/43211, plus a Live Protect shield pending fixed NX-OS upgrades. The Register also says Cisco has not observed attacks against these flaws, and Security Affairs notes PSIRT was unaware of public disclosure or malicious exploitation at disclosure time. Sources disagree on how the flaw was found: Security Affairs says Cisco TAC discovered it during a support case, while The Register describes all the flaws, including this one, as stemming from a comprehensive internal security review. Separately, Cisco patched seven vulnerabilities in IOS XR, its Linux-based carrier-grade network operating system, all found via internal testing. Two are critical, CVSS 9.8 lifetime resource control issues — CVE-2026-20274 and CVE-2026-20279 — that can enable unauthenticated remote code execution with root access; the other five are rated 8.2–8.8 and involve buffer overflows, access control failures, and out-of-bounds access. All IOS XR releases, including IOS XR7, are affected regardless of configuration, and no workarounds exist: remediation requires software maintenance upgrades (SMUs) or fixed releases 26.2.2 and 26.3.1 (The Register characterizes the fixed versions as newly released; CSO Online calls them future fixed releases). Cisco says none of the flaws are known to be actively exploited, but experts urge immediate patching of internet-facing and core routing systems, citing parallels with Salt Typhoon tradecraft and recommending supplier exposure audits.

  • CVE-2026-20212 (CVSS 9.8): unauthenticated remote root code execution in the Silicon One integration of certain Nexus 9000 Series switches
  • Attack surface: TCP ports 43210 and 43211 exposed through the default Layer 3 VRF; exploitation can also crash the S1HAL process and force device reloads
  • Scope: only Nexus 9000 switches with Silicon One ASICs; ACI mode and Nexus 3000/7000 unaffected; The Register reports ten affected Nexus 9000 models
  • CVE-2026-20212 mitigation: infrastructure ACLs (iACLs) or blocking traffic to ports 43210/43211, plus a Live Protect shield; no fixed NX-OS release available yet at disclosure
  • IOS XR: seven internally discovered vulnerabilities patched; two rated CVSS 9.8 (CVE-2026-20274, CVE-2026-20279), lifetime resource control issues enabling unauthenticated RCE with root access; other five rated 8.2–8.8 (buffer overflows,…
  • IOS XR scope: all releases, including IOS XR7, affected regardless of configuration; no workarounds; remediation requires SMUs or fixed releases 26.2.2 and 26.3.1
  • Discovery: IOS XR flaws found via internal review/testing; sources disagree on CVE-2026-20212 — Security Affairs says Cisco TAC found it during a support case, The Register attributes all flaws to a comprehensive internal security review
  • Exploitation: Cisco says no active exploitation or malicious use observed/known at disclosure; PSIRT unaware of public disclosure (per Security Affairs); SOCRadar's excerpt reports no exploitation

Coverage timeline

  1. · 12d ago
    Security Affairs· 64
    Cisco Fixed Critical RCE in Nexus 9000 Series Switches

    Cisco patched CVE-2026-20212 (CVSS 9.8) in Silicon One-based Nexus 9000 switches, allowing unauthenticated remote root code execution via TCP ports 43210/43211.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20212
Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration

CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.

Do: Inventory your Nexus 9000 fleet to identify Silicon One–integrated models and test whether TCP ports 43210/43211 are reachable in the default L3 VRF (e.g., nmap the management/default VRF or review interface and control-plane ACLs). Upgrade to the fixed software release listed in Cisco's advisory published September 2, 2026. As an interim mitigation, restrict access to ports 43210 and 43211 via ACLs and monitor for S1HAL process crashes or unexpected device reloads.

9.8<1%
  • Cisco Nexus 9000 Series Switches with Silicon One integration
large≈ tens of thousands of deployed switches plausibly in the affected subset (Silicon One–based Nexus 9000 models), of which likely only a few thousand have TCP…
CVE-2026-20274
+1 in the same advisory: …20279
Critical Improper Resource Control Flaws in Cisco IOS XR Software

CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days.

Do: Upgrade affected IOS XR devices to the security/hardening release bundled in Cisco's September 2, 2026 advisory batch, checking that advisory for the exact fixed release for your version train. Until patching is complete, restrict network reachability of IOS XR management and control planes to trusted operators, since the flaws require no authentication or user interaction. Organizations also running Cisco Nexus 9000 switching should review the separate, same-day NX-OS advisory for the unauthenticated root RCE reported in related coverage.

9.8<1%
  • Cisco IOS XR Software
large≈10^5 (on the order of ~100,000) internet-exposed IOS XR devices per public scan counts; total deployed fleet, including carrier-internal routers, is larger…