securityaffairs.com 9/3/2026, 8:30:28 PM · external

Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Cisco Fixed Critical RCE in Nexus 9000 Series Switches
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CISCO has patched a critical vulnerability (CVE-2026-20212) in its Nexus 9000 series switches that allows unauthenticated remote code execution with a CVSS score of 9.8. Discovered during a customer support investigation, the flaw arises from the exposure of TCP ports 43210 and 43211, enabling attackers to execute code with root privileges. This flaw affects specific Nexus 9000 models using Silicon One ASICs.

Cisco recommends using infrastructure access control lists (iACLs) as a workaround and encourages upgrading to a patched NX-OS release for a permanent solution, as no public exploitation of the vulnerability has been reported.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline