Cyber Security News

Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Code

Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

Tracked as CVE-2026-20212, the flaw has received a CVSS score of 9.8 out of 10 and affects Nexus 9000 models that use a Silicon One ASIC. The security issue, identified as CWE-1327, is detailed in Cisco advisory cisco-sa-n9k-s1-rce-EH8dEtr, published on September 2, 2026.

Cisco said the vulnerability was discovered while resolving a Technical Assistance Center support case. At the time of publication, Cisco PSIRT said it was not aware of public exploitation or malicious activity involving the flaw.

The vulnerability exists because TCP ports 43210 and 43211 are reachable through the default Layer 3 virtual routing and forwarding configuration on affected devices. An attacker does not need valid credentials to target the vulnerable service.

By connecting to an exposed switch and sending specially crafted input, an attacker could cause that input to be executed as code with root-level privileges.

Cisco Nexus 9000 Series Switches Vulnerability

Root access would give an attacker broad control over the targeted switch. This could enable changes to network configuration, traffic monitoring, service disruption, data interception, or movement to other systems connected to the network.

Successful exploitation can also crash the S1HAL process, Cisco warned, potentially forcing the affected device to reload and causing a network outage. The issue affects Cisco Nexus 9000 Series Switches that include a Silicon One ASIC.

Cisco listed several affected product identifiers, including N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808.

Administrators can identify the installed module and product identifier by running the show module command on the switch. Organizations should compare the returned model number against Cisco’s affected-product list and then verify whether their current NX-OS release is vulnerable through the Cisco Software Checker.

Cisco confirmed that other Nexus 9000 models not listed in the advisory are not affected. Nexus 9000 Fabric Switches operating in ACI mode are also not vulnerable.

Other confirmed unaffected products include Nexus 3000 and Nexus 7000 Series Switches, MDS 9000 Series Multilayer Switches, Cisco Firepower appliances, Secure Firewall products, and several UCS Fabric Interconnect platforms.

Cisco has released software updates to address CVE-2026-20212 and strongly recommends upgrading to a fixed NX-OS release. Until patching is complete, organizations can apply infrastructure access control lists to permit only necessary management and control-plane traffic to the device.

As an additional mitigation, administrators can configure iACLs to explicitly deny TCP traffic sent to locally configured switch IP addresses on destination ports 43210 and 43211.

Cisco also released a Live Protect shield for temporary protection, but stressed that it should only serve as a bridge until a full software upgrade is deployed.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

4 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

15 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

16 hours ago