Cisco Patches Critical Flaws in Nexus 9000 Switches and IOS XR Software
Cisco Systems has rolled out patches to address critical security flaws affecting its Silicon One-based Nexus 9000 switches and IOS XR software. The company released a fix for a vulnerability, known as CVE-2026-20212, that could allow unauthenticated attackers to execute code with root privileges on the switches.
The flaw allows hackers to bind to an unrestricted IP address and reach TCP ports 43210 and 43211, potentially leading to a device reload. While Cisco is not aware of any malicious use of this vulnerability, it recommends customers upgrade to fixed releases or apply temporary mitigations like infrastructure access control lists (iACLs).
Separately, Cisco released an IOS XR hardening update that addresses seven vulnerabilities, two of which have a CVSS score of 9.8. These vulnerabilities affect all IOS XR releases, and the company is providing software maintenance updates for various versions, with fixed releases expected soon.