Cisco fixes critical root code execution risk in Nexus 9000 switches

Cisco has released fixes and mitigations for CVE-2026-20212, a critical vulnerability affecting 10 Silicon One-based Nexus 9000 switch models. The flaw carries a CVSS score of 9.8 and could allow an unauthenticated remote attacker to execute code with root privileges if they can reach the affected switch on TCP port 43210 or 43211.
The issue stems from binding a service to an unrestricted IP address, leaving the ports accessible in the default Layer 3 virtual routing and forwarding instance. Cisco said crafted input sent to that service can be executed as code with root privileges. An attack attempt can also crash the S1HAL process and trigger a device reload.
Cisco said it was unaware of malicious exploitation when it disclosed the issue on September 2. The affected product identifiers include the N9324C-SE1U and N9348Y2C6D-SE1U Nexus Smart Switches, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804 and N9K-C9808.
Exposure depends on reachable management services
Other Nexus 9000 models, Nexus 9000 fabric switches running in Application Centric Infrastructure mode, and the Nexus 3000 and 7000 families are not affected. Cisco directs customers to its Software Checker rather than publishing a fixed-release table. The CVE record lists 45 affected NX-OS releases, from 10.3(1) through 10.6(3s).
Until a confirmed fixed release is available, Cisco recommends an infrastructure access control list that permits only necessary management and control-plane traffic, or explicitly denies TCP traffic to a locally configured IP address on ports 43210 and 43211. Cisco also offers the temporary Live Protect shield lp00031 for NX-OS 10.6(3), with a second package for 10.6(3s) on the two Smart Switches. The shield is not supported on Nexus 9804 and 9808 platforms and requires SSH, Telnet or NX-API access.
IOS XR hardening release expands the remediation workload
The same disclosure cycle included an IOS XR hardening release covering seven umbrella CVEs. CVE-2026-20274, for memory-safety and resource-lifetime issues, and CVE-2026-20279, for access-control issues including missing authentication for critical functions and improper certificate validation, each have a maximum CVSS score of 9.8. The remaining five CVEs range from 8.2 to 8.8.
All IOS XR releases are affected regardless of device configuration, Cisco said. XR7 LNT platforms, including the Cisco 8000 Series, NCS 1010, NCS 540L and NCS 5700 Series, have a dedicated SMU that applies across releases. Cisco expects future releases 26.2.2 and 26.3.1 to be the first fixed versions that do not require SMUs.
The operational urgency is reinforced by Cisco vulnerabilities and ClickFix attack chains tracking Cisco vulnerabilities alongside ClickFix chains and rising AI-agent incidents. Businesses operating the affected Nexus platforms should verify hardware identifiers, limit reachability to the two exposed ports, and plan the Cisco-recommended upgrade or SMU deployment through their change-control process.

