Cisco AI Data Center Switches Exposed to Root Compromise
Cisco recently disclosed a critical vulnerability in its Nexus 9000 switches equipped with Silicon One ASICs, which has left AI data centers vulnerable to root compromise.
The flaw, designated as CVE-2026-20212, allows for unauthenticated remote code execution (RCE) via TCP ports 43210 and 43211 in the default L3 VRF. With a CVSS score of 9.8, this vulnerability is one of the most severe.
The affected hardware serves as the backbone for modern AI data centers, facilitating massive GPU-to-GPU RDMA traffic required for training and inference in clusters exceeding one million GPUs. The Silicon One ASIC is designed for high-bandwidth 400G and 800G Ethernet, making it a critical component in the fabric of AI infrastructure.
Security professionals must move beyond an application-centric view of AI security, as the emergence of vulnerabilities like CVE-2026-20212 demonstrates that AI data center infrastructure is now a primary attack surface. An attacker gaining root access to the network fabric can intercept or manipulate traffic between GPUs, effectively bypassing security controls implemented at the software or framework layer.