🔴 Critical: Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
-
Cisco has shipped patches addressing a critical vulnerability in the Nexus 9000 line, specifically impacting models built on the Silicon One architecture. The flaw, CVE-2026-20212 with a CVSS score of 9.8, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The issue stems from improper handling of certain packets, and successful exploitation could lead to a full system compromise.
The advisory confirms that 10 distinct Nexus 9000 switch models are affected by this vulnerability. Cisco has also released a broader IOS XR hardening bundle which includes fixes for seven umbrella CVEs, two of which carry the maximum severity rating of 9.8. At this time, Cisco has stated there is no workaround available for any of the affected IOS XR versions; administrators are urged to apply the provided software updates as soon as possible.
Key details for network administrators:
- Affected product line: Nexus 9000 Series switches (Silicon One-based models).
- Primary vulnerability: CVE-2026-20212 (CVSS 9.8).
- Risk: Remote code execution as root without requiring authentication.
- Mitigation: No workaround exists; apply the latest IOS XR patch release immediately.
If you operate any of the affected switching hardware, check your current IOS XR version against the patched release notes and schedule maintenance accordingly.
Source: The Hacker News
Since there is no workaround for this flaw, are you planning an emergency maintenance window to patch your Nexus 9000 fleet, or have you already segmented those devices to limit exposure?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login