Cisco has issued fixes for a critical security vulnerability in 10 Silicon One-based Nexus 9000 switches that could let an unauthenticated, remote attacker run code with root privileges, according to a September 2 disclosure on The Hacker News. The company also released an IOS XR hardening update bundling seven umbrella CVEs, two of which scored 9.8 out of 10, with no workaround available for any IOS XR version. Cisco said it's not aware of any malicious exploitation of the Nexus flaw as of the disclosure date.
The Nexus vulnerability, designated CVE-2026-20212 with a CVSS score of 9.8, stems from binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 accessible in the default Layer 3 virtual routing and forwarding instance. An attacker who can reach a switch's address on either port can connect straight to the service, the report states. Specially crafted input sent to that service then executes as code with root access. An exploit attempt can also crash the S1HAL process and force the device to reload. The Hacker News verified through the CVE Program's record on September 3 that Cisco lists 45 NX-OS releases, spanning 10.3(1) through 10.6(3s), as vulnerable. Affected product identifiers include the N9324C-SE1U and N9348Y2C6D-SE1U Nexus Smart Switches, the N9364E-SG2-O and N9364E-SG2-Q, the N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808. Other Nexus 9000 models, Nexus 9000 fabric switches running in Application Centric Infrastructure mode, and the Nexus 3000 and 7000 lines aren't affected.
Cisco hasn't published a fixed-release table and instead directs customers to its Software Checker, the disclosure notes. Temporary stopgaps include an infrastructure access control list blocking the two ports and a Live Protect shield. Until a fixed release is confirmed, Cisco recommends upgrading to the release identified by its Software Checker, deploying an iACL that permits only required management and control-plane traffic or explicitly blocks TCP packets to a locally configured IP address on destination port 43210 or 43211, and using Live Protect shield lp00031, though that's supported only on NX-OS 10.6(3) and 10.6(3s) for the two Smart Switches and isn't compatible with the Nexus 9804 and 9808. "At the same time, the window between disclosure and exploitation has effectively closed," Russ Smoak, vice president of information security at Cisco, said in a June blog post announcing the twice-monthly disclosure model that groups internally found bugs into umbrella CVEs. The IOS XR hardening release assigns one CVE to each Common Weakness Enumeration bucket of patched bugs and scores it at the most severe defect in that bucket. CVE-2026-20274, covering memory-safety and resource-lifetime bugs, and CVE-2026-20279, covering access-control bugs including missing authentication for critical functions and improper certificate validation, each carry a 9.8 ceiling. The remaining five, CVE-2026-20275 through 20278 and CVE-2026-20280, top out between 8.2 and 8.8.
The vulnerabilities affect all IOS XR releases regardless of device configuration, the hardening advisory said. Software maintenance updates are available for 15 releases, including 6.9.2, 7.3.2, 7.9.2, 7.9.21, 7.10.2, 7.11.2, 7.11.21, 24.2.2, 24.2.21, 24.4.2, 25.2.21, 25.4.1, 25.4.2, 26.1.2, and 26.2.1, with SMUs listed as future releases for 24.1.2, 24.3.2, 25.1.2, and 25.2.2. The Hacker News cross-checked the seven CVE records against the advisory on September 3 and found that, of the 111 IOS XR releases Cisco lists as affected, 14 have SMUs available today, four are awaiting SMUs, and 93 must first be upgraded before a fix can be applied. Future releases 26.2.2 and 26.3.1 will be the first fixed releases needing no SMUs. The disclosure comes six days after Sygnia reported that the China-linked threat actor Fire Ant, first documented in 2025, ran purpose-built implants on IOS XR routers that suppressed syslog delivery, filtered show command output, and supported a hidden Generic Routing Encapsulation tunnel. The actor also captured packets from routers, uploaded them to external FTP servers, and made connection attempts and port scans against connected systems tied to critical infrastructure. The investigation began with a tunnel interface active on a router with no running configuration or commit history to explain it, suggesting the device's operational state could no longer be trusted to match the configuration and audit records. Organizations operating affected Cisco infrastructure should prioritize patching timelines given the compressed window between public disclosure and potential weaponization. The convergence of vendor-acknowledged flaws and active state-sponsored router compromise campaigns underscores the strategic value attackers now place on network control-plane access.

