Cisco Nexus 9000 Flaw Lets Attackers Run Code as Root via Exposed Ports
Cisco has disclosed a critical security vulnerability, tracked as CVE-2026-20212, affecting 10 Silicon One-based Nexus 9000 switches and carrying a maximum CVSS score of 9.8. The flaw stems from the switches binding to an unrestricted IP address, leaving TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance. An unauthenticated remote attacker who can reach either port can deliver crafted input that is executed as code with root privileges, while a failed exploitation attempt may crash the S1HAL process and force a device reload. As of the September 2 disclosure, Cisco stated it was not aware of any malicious exploitation in the wild. Security teams can use a port scanner to verify whether either port is exposed on their network edge.
The affected hardware includes the N9324C-SE1U and N9348Y2C6D-SE1U Nexus Smart Switches, the N9364E-SG2-O and N9364E-SG2-Q, the N9396T12C-SE1, N9348Y12C-SE1, and N9396Y12C-SE1, along with the N9336C-SE1, N9K-C9804, and N9K-C9808 chassis models. Cisco's advisory lists 45 NX-OS releases spanning versions 10.3(1) through 10.6(3s) as vulnerable, though the company declined to publish a fixed-release table and instead directed administrators to its Software Checker tool. Other Nexus 9000 series switches, units running in Application Centric Infrastructure (ACI) mode, and the Nexus 3000 and 7000 lines are not affected.
Because no patched firmware has been confirmed, Cisco recommends a three-part mitigation strategy. Administrators should first upgrade to the release named by the Software Checker, noting that the Live Protect shield's operational mode transitions to N/A on NX-OS 10.6(4) or higher. They should also deploy an infrastructure access control list (iACL) that explicitly denies TCP packets destined for any locally configured IP address on ports 43210 or 43211, validated in a test environment. Finally, the temporary Live Protect shield lp00031 can be applied on NX-OS 10.6(3), with a second shield package available for 10.6(3s) on the two Smart Switches, though the shield is unsupported on the Nexus 9804 and 9808 chassis. Network defenders auditing exposure can cross-reference their public-facing IP ranges with a WHOIS lookup to identify which assets are reachable from the internet.
Alongside the Nexus advisory, Cisco shipped an IOS XR hardening release bundling seven umbrella CVEs, two of which are rated 9.8, with no available workaround for any IOS XR version. Customers running IOS XR7 (LNT) and other branches are urged to upgrade to a release containing the relevant software maintenance updates (SMUs) and apply them immediately. The disclosure reflects Cisco's new twice-monthly bundled vulnerability model, introduced by VP of information security Russ Smoak, which groups internally discovered flaws under umbrella CVEs to compress the window between disclosure and patching. Organizations managing multi-vendor network estates should review their segmentation policies and verify that management-plane traffic is locked down with strict ACLs, while a SSL/TLS checker can help confirm that adjacent services are not also exposing encrypted channels without proper authentication.