Cisco discloses critical Nexus 9000 root RCE (CVE-2026-20212) and bundles seven IOS XR flaws — including CVE-2026-20274 and CVE-2026-20279 — into September 2026 releases
Cisco is addressing critical vulnerabilities found through internal review: CVE-2026-20212 (CVSS 9.8), an unauthenticated remote root code execution flaw in Silicon One-based Nexus 9000 switches exposed via TCP ports 43210/43211, and seven IOS XR…
Cisco has disclosed a set of critical vulnerabilities in its networking products, all discovered through internal review. The most severe is CVE-2026-20212 (CVSS 9.8), a flaw in the Silicon One integration used by certain Nexus 9000 Series switches that allows an unauthenticated remote attacker to execute code with root privileges by reaching TCP ports 43210 and 43211, which are exposed through the default Layer 3 VRF; exploitation can also crash the S1HAL process and force device reloads. Per Security Affairs, only Nexus 9000 switches with Silicon One ASICs are affected — ACI mode and Nexus 3000/7000 are unaffected — and The Register puts the count at ten affected Nexus 9000 models. Sources disagree on remediation status: Security Affairs says Cisco patched the flaw with workarounds (infrastructure ACLs or blocking the exposed ports) plus a temporary Live Protect shield pending fixed NX-OS upgrades, while The Register states no permanent software fix exists yet and mitigation is limited to iACLs; SOCRadar's excerpt provides no patch details. Discovery attribution also differs slightly: Security Affairs attributes the find to Cisco TAC during a support case, The Register and CSO Online to a comprehensive internal security review. Separately, Cisco patched seven internally discovered vulnerabilities in IOS XR, the Linux-based OS for carrier-grade routers. Two — CVE-2026-20274 and CVE-2026-20279, both CVSS 9.8 — are lifetime resource control issues enabling unauthenticated remote code execution with root access; the other five, rated 8.2–8.8, cover buffer overflows, access control failures, and out-of-bounds access. All IOS XR releases, including IOS XR7, are affected regardless of configuration, no workarounds exist, and remediation requires software maintenance upgrades (SMUs) or fixed releases 26.2.2 and 26.3.1. Canada's Cyber Centre (advisory AV26-876, 2026-09-03) also relayed Cisco SIP software denial-of-service flaws affecting Desk Phone 9800, IP Phone 7800/8800, and Video Phone 8875 (no CVEs given in the reports). Cisco says none of the flaws are known to be actively exploited; experts urge immediate patching of internet-facing and core routing systems, citing parallels with Salt Typhoon tradecraft.
- CVE-2026-20212 (CVSS 9.8): unauthenticated remote root code execution in the Silicon One integration of certain Nexus 9000 Series switches (ten models per The Register); ACI mode and Nexus 3000/7000 unaffected (Security Affairs).
- The Nexus flaw is exposed via TCP ports 43210 and 43211 in the default Layer 3 VRF; exploitation can crash the S1HAL process and force device reloads (Security Affairs).
- Remediation status for CVE-2026-20212 is disputed: Security Affairs reports it patched, with iACLs/port blocking and a Live Protect shield pending fixed NX-OS upgrades; The Register says no permanent software fix exists yet and only iACL…
- IOS XR: seven internally discovered vulnerabilities fixed; CVE-2026-20274 and CVE-2026-20279 (both CVSS 9.8, critical) are lifetime resource control issues enabling unauthenticated RCE with root access; the other five are rated 8.2–8.8…
- All IOS XR releases, including IOS XR7, are affected regardless of device configuration; no workarounds exist; remediation requires SMUs or fixed releases 26.2.2 and 26.3.1 (CSO Online).
- Canada's Cyber Centre advisory AV26-876 (2026-09-03) relayed Cisco advisories covering the Nexus 9000 Silicon One RCE, a September 2026 IOS XR hardening release, and SIP software DoS flaws in Desk Phone 9800, IP Phone 7800/8800, and Video…
- Discovery attribution differs: Cisco TAC found CVE-2026-20212 during a support case (Security Affairs); The Register and CSO Online describe a comprehensive internal security review covering the flaws.
- Cisco PSIRT reports no public disclosure or malicious/active exploitation of the flaws at disclosure time; experts nonetheless urge immediate patching of internet-facing and core routers, citing Salt Typhoon tradecraft parallels.
Coverage timelineoldest first · each row is one article
- · 12d agoCisco security advisory (AV26-876)
Canadian Centre for Cyber Security· 26
Canada's Cyber Centre relayed Cisco advisories covering a Nexus 9000 Silicon One RCE, IOS XR hardening, and denial-of-service flaws across IP phone lines.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20212 | Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days. Do: Inventory your Nexus 9000 fleet to identify Silicon One–integrated models and test whether TCP ports 43210/43211 are reachable in the default L3 VRF (e.g., nmap the management/default VRF or review interface and control-plane ACLs). Upgrade to the fixed software release listed in Cisco's advisory published September 2, 2026. As an interim mitigation, restrict access to ports 43210 and 43211 via ACLs and monitor for S1HAL process crashes or unexpected device reloads. | 9.8 | <1% |
| large≈ tens of thousands of deployed switches plausibly in the affected subset (Silicon One–based Nexus 9000 models), of which likely only a few thousand have TCP… | ||
| CVE-2026-20274 +1 in the same advisory: …20279 | Critical Improper Resource Control Flaws in Cisco IOS XR Software CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days. Do: Upgrade affected IOS XR devices to the security/hardening release bundled in Cisco's September 2, 2026 advisory batch, checking that advisory for the exact fixed release for your version train. Until patching is complete, restrict network reachability of IOS XR management and control planes to trusted operators, since the flaws require no authentication or user interaction. Organizations also running Cisco Nexus 9000 switching should review the separate, same-day NX-OS advisory for the unauthenticated root RCE reported in related coverage. | 9.8 | <1% |
| large≈10^5 (on the order of ~100,000) internet-exposed IOS XR devices per public scan counts; total deployed fleet, including carrier-internal routers, is larger… |