Cisco patches critical Nexus 9000 root RCE (CVE-2026-20212) and expands IOS XR fix bundle to seven vulnerabilities from internal security review
Cisco's internal security review surfaced CVE-2026-20212, a critical unauthenticated remote code execution flaw with root privileges in the Silicon One integration of certain Nexus 9000 switches (reachable via TCP ports 43210/43211 in the default Layer 3…
On 2026-09-02, Cisco published an advisory for a vulnerability in the Silicon One integration used by certain Nexus 9000 Series switches, identified in follow-up coverage as CVE-2026-20212. The flaw allows an unauthenticated remote attacker to execute code with root privileges by reaching TCP ports 43210 and 43211, which are accessible in the default Layer 3 VRF; exploitation may also crash the S1HAL process and force the affected device to reload. The Register's 2026-09-04 report adds that the flaw affects ten Nexus 9000 models and was found during a comprehensive internal security review. Source disagreement: on patch availability for CVE-2026-20212, the Cisco advisory (2026-09-02) states software updates have been released and workarounds are available, while The Register (2026-09-04) states no permanent software fix exists yet and exposure is mitigated via infrastructure ACLs (iACLs). SOCRadar's 2026-09-04 coverage likewise rated the flaw critical but offered no patch details. The same internal review surfaced critical flaws in IOS XR, Cisco's Linux-based network operating system for carrier-grade routers. The Register (2026-09-04) reported two, CVE-2026-20274 and CVE-2026-20279, both rated CVSS 9.8 and fixed in newly released versions. CSO Online's 2026-09-09 report expands the tally to seven IOS XR vulnerabilities in total: the two CVSS 9.8 critical flaws stem from lifetime resource control issues that can enable unauthenticated remote code execution with root access, while the other five are rated 8.2–8.8 and cover buffer overflows, access control failures, and out-of-bounds access. According to CSO Online, all IOS XR releases — including IOS XR7 — are affected regardless of device configuration; no workarounds exist, and remediation requires software maintenance upgrades (SMUs) or the fixed releases 26.2.2 and 26.3.1. On exploitation, Cisco says it has not observed attacks against the flaws (The Register, 2026-09-04) and the IOS XR flaws are not known to be actively exploited (CSO Online, 2026-09-09); SOCRadar also reported no exploitation. Despite the absence of observed attacks, experts cited by CSO Online urge immediate patching of internet-facing and core routing systems and auditing of supplier exposure, citing parallels with Salt Typhoon tradecraft.
- CVE-2026-20212 (critical): unauthenticated remote code execution with root privileges in the Silicon One integration of certain Nexus 9000 Series switches, reachable via TCP ports 43210 and 43211 in the default Layer 3 VRF; affects ten…
- Exploitation of CVE-2026-20212 may crash the S1HAL process and force the affected device to reload
- Patch availability for CVE-2026-20212 is disputed: Cisco's 2026-09-02 advisory says software updates and workarounds are available; The Register (2026-09-04) says no permanent software fix exists yet, with iACL mitigations only
- CVE-2026-20274 and CVE-2026-20279 (IOS XR, both CVSS 9.8 critical): lifetime resource control issues enabling unauthenticated remote code execution with root access
- Seven IOS XR vulnerabilities in total per CSO Online: two CVSS 9.8 and five rated 8.2–8.8 (buffer overflows, access control failures, out-of-bounds access)
- All IOS XR releases, including IOS XR7, are affected regardless of device configuration
- IOS XR remediation: no workarounds; requires software maintenance upgrades (SMUs) or fixed releases 26.2.2 and 26.3.1 (CSO Online); The Register (2026-09-04) reported the two critical flaws as fixed in newly released versions
- All flaws were found during a comprehensive internal Cisco security review
Coverage timelineoldest first · each row is one article
- · 14d agoCisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
Cisco Security Advisories· 62
Cisco patches unauthenticated RCE in Nexus 9000 Silicon One switches exposed via TCP ports 43210 and 43211 in the default L3 VRF.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20212 | Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days. Do: Inventory your Nexus 9000 fleet to identify Silicon One–integrated models and test whether TCP ports 43210/43211 are reachable in the default L3 VRF (e.g., nmap the management/default VRF or review interface and control-plane ACLs). Upgrade to the fixed software release listed in Cisco's advisory published September 2, 2026. As an interim mitigation, restrict access to ports 43210 and 43211 via ACLs and monitor for S1HAL process crashes or unexpected device reloads. | 9.8 | <1% |
| large≈ tens of thousands of deployed switches plausibly in the affected subset (Silicon One–based Nexus 9000 models), of which likely only a few thousand have TCP… | ||
| CVE-2026-20274 +1 in the same advisory: …20279 | Critical Improper Resource Control Flaws in Cisco IOS XR Software CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days. Do: Upgrade affected IOS XR devices to the security/hardening release bundled in Cisco's September 2, 2026 advisory batch, checking that advisory for the exact fixed release for your version train. Until patching is complete, restrict network reachability of IOS XR management and control planes to trusted operators, since the flaws require no authentication or user interaction. Organizations also running Cisco Nexus 9000 switching should review the separate, same-day NX-OS advisory for the unauthenticated root RCE reported in related coverage. | 9.8 | <1% |
| large≈10^5 (on the order of ~100,000) internet-exposed IOS XR devices per public scan counts; total deployed fleet, including carrier-internal routers, is larger… |