Anyone who can reach a vulnerable Nexus 9000 switch over the network can become root on it, Cisco warned this week as it detailed a critical flaw uncovered during a customer support investigation. The issue, CVE-2026-20212, scores 9.8 on the CVSS scale and affects switches built on the company’s Silicon One ASICs.
Because one service binds to an unrestricted address, TCP ports 43210 and 43211 end up reachable inside the default Layer 3 VRF instance. Once connected, the attacker can push crafted input at the service and gain root-level execution. Even a failed attack can crash the S1HAL process, which reboots the switch.
Ten models are on the affected list so far, among them the N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9396T12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808. To tell whether hardware is exposed, administrators compare the product identifier printed by the show module command against the advisory. Everything off that list stays clear, including Nexus 9000 gear in ACI mode and the Nexus 3000 and 7000 lines.
No public exploit or active misuse was known as of the September 2 disclosure, Cisco says. Because no fixed-release table was published, the vendor is steering customers to its Software Checker to identify the right NX-OS upgrade. Two stopgaps are offered meanwhile: an infrastructure access control list that blocks TCP traffic to the two ports, and a temporary Live Protect shield.
The advisory spans 45 NX-OS releases from 10.3(1) through 10.6(3s). Cisco’s same-day batch also shipped an IOS XR hardening release bundling seven umbrella CVEs, two rated 9.8.
