Cisco Fixes Critical RCE Vulnerability in Nexus 9000 Series Switches
Cisco has addressed a critical remote code execution vulnerability in its Nexus 9000 Series Switches. The flaw, tracked as CVE-2026-20212, is rated CVSS score of 9.8 and affects 10 Silicon One-based Nexus 9000 switches.
The vulnerability allows an unauthenticated attacker to execute code with root privileges by connecting remotely and sending specially crafted data through TCP ports 43210 and 43211, which are exposed in the default Layer 3 VRF. This could also crash the S1HAL process, potentially causing the affected device to reload.
Cisco's Technical Assistance Center discovered the flaw while investigating a customer support case. The company has released patches for the vulnerability and provides a workaround to reduce the risk of remote exploitation by using infrastructure access control lists (iACLs) or blocking TCP traffic to locally configured IP addresses on ports 43210 and 43211.
Cisco recommends upgrading to a fixed NX-OS release as the permanent solution. The company's Product Security Incident Response Team is not aware of any public disclosure or active exploitation of this vulnerability.