Critical Cisco Nexus 9000 Flaw Exposes Network Devices to Remote Attacks
Cisco has released security updates to address a critical vulnerability in its Nexus 9000 Series switches. The flaw, tracked as CVE-2026-20212, allows unauthenticated remote attackers to execute arbitrary code with root privileges.
The issue originates from the integration of Silicon One in affected Cisco NX-OS deployments, which exposes TCP ports 43210 and 43211 through the default Layer 3 virtual routing and forwarding (VRF) instance. This creates a network-reachable attack surface that doesn't require valid device credentials.
An attacker could exploit this vulnerability by connecting to an exposed Nexus switch and sending specially crafted input to the vulnerable service, resulting in complete device compromise or denial-of-service condition.