Critical Cisco Vulnerability Allows Remote Root Access
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches. The vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), allows an unauthenticated, remote attacker to execute code as root.
The issue arises from binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance. An attacker who can reach a switch's address on either port can connect directly to the service, execute crafted input as code with root privileges, and potentially crash the S1HAL process and reload the device.
Cisco is not aware of any malicious use of the flaw as of its September 2 disclosure. The company has published no fixed-release table but directs customers to its Software Checker. Customers are advised to upgrade to a release that includes software maintenance updates (SMUs), then apply them, or implement an infrastructure access control list (iACL) blocking the two ports and using a temporary Live Protect shield as stopgaps.