CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

September 3, 2026

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root Swati KhandelwalSep 03, 2026Vulnerability / Network Security Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance. An attacker who can reach a switch's address on…

CVEs: CVE-2026-20212, CVE-2026-20274, CVE-2026-20279, CVE-2026-20275, CVE-2026-20280, CVE-2026-20354, CVE-2026-20355, CVE-2026-20281