- CVE: CVE-2026-20212
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Cisco NX-OS Software
- Affected: 10.3(1), 10.3(2), 10.3(3), 10.4(1), 10.3(99w), 10.3(3w) (+39 more)
- Impact: Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
- Status: No confirmed exploitation yet
- Action: See vendor advisory
TL;DR
Cisco disclosed CVE-2026-20212 on September 2, 2026. This critical Cisco Nexus 9000 vulnerability allows unauthenticated remote code execution with root privileges. It affects switches that include a Silicon One ASIC and scores 9.8 on the CVSS scale.
Why It Matters
Nexus 9000 switches carry traffic across many data center networks. Therefore, root-level control of one switch is a serious event. This Cisco Nexus 9000 vulnerability needs no credentials and no user interaction.
A successful attacker runs code as root on the device. Beyond code execution, the flaw can crash a core process. According to Cisco, that crash could cause the device to reload.
How the Attack Works
The flaw stems from the Silicon One hardware abstraction layer. Cisco explains it exists because “TCP ports 43210 and 43211 are accessible in the default” Layer 3 VRF. An attacker connects to those open ports.
From there, the attacker sends crafted input to the device. The advisory warns this input “could be executed as code with root privileges”. This report withholds any exploit detail.
Exploitation Status
Cisco reports no active exploitation. Its PSIRT is not aware of any public announcements or malicious use. The flaw surfaced during a Cisco TAC support case. Still, the 9.8 severity makes fast action wise.
Affected Versions
The bug affects Nexus 9000 Series Switches that include a Silicon One ASIC. Affected models include the N9336C-SE1, N9K-C9804, and N9K-C9808, among others. Use the show module command to check your device PID. Other Nexus platforms and ACI-mode fabric switches are not affected.
Patch and Mitigation Steps
Cisco has released free software updates that fix the flaw. Use the Cisco Software Checker to find the right release.
If You Cannot Patch Now
Apply infrastructure access control lists to block the risk. The iACLs should deny TCP traffic to ports 43210 and 43211. Cisco also offers a Live Protect shield as a temporary measure. Test any workaround before you deploy it in production.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!