Critical Cisco Flaw Lets Attackers Execute Code as Root
Cisco has disclosed a critical remote code execution vulnerability in its Nexus 9000 Series Switches equipped with Silicon One ASICs. This flaw, tracked as CVE-2026-20212, could allow unauthenticated attackers to run arbitrary code with root privileges.
The vulnerability exists in the Silicon One integration used by specific Cisco Nexus 9000 platforms. According to Cisco, TCP ports 43210 and 43211 are accessible through the default Layer 3 virtual routing and forwarding (VRF) instance.
An unauthenticated remote attacker could connect to an exposed affected switch and send specially crafted input to these ports. Successful exploitation could result in attacker-supplied code being executed with root-level privileges on the device.