Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root: A Global Security Concern




A critical security flaw in Cisco's Nexus 9000 switches has been identified, allowing unauthenticated remote attackers to execute code as root. This vulnerability has been rated as high-severity, with a CVSS score of 9.8, making it a serious concern for organizations that rely on these switches for their network infrastructure. Cisco has released patches and an IOS XR hardening release that includes fixes for 111 IOS XR releases, and customers are advised to take immediate action to upgrade to a release that includes SMUs and apply them as soon as possible.

  • Unauthenticated remote attackers can execute code as root on Cisco's Nexus 9000 switches.
  • The vulnerability has a CVSS score of 9.8, making it a high-severity concern.
  • The vulnerability affects 10 Silicon One-based Nexus 9000 switches and other Cisco products, including Nexus 3000 and 7000 lines.
  • Cisco has released patches and an IOS XR hardening release to address the issue.
  • Customers are advised to take immediate action to upgrade to a release that includes software maintenance updates (SMUs) and apply them as soon as possible.



  • A critical security flaw in Cisco's Nexus 9000 switches has been identified, allowing unauthenticated remote attackers to execute code as root. This vulnerability has been rated as high-severity, with a CVSS score of 9.8, making it a serious concern for organizations that rely on these switches for their network infrastructure.

    The vulnerability, tracked as CVE-2026-20212, is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance. An attacker who can reach a switch's address on either port can connect directly to the service, allowing them to execute crafted input as code with root privileges.

    The vulnerability affects 10 Silicon One-based Nexus 9000 switches, and Cisco has released patches to address the issue. However, due to the critical nature of the flaw, customers are advised to take immediate action to upgrade to a release that includes software maintenance updates (SMUs) and apply them as soon as possible.

    The vulnerability was first disclosed by Cisco on September 2, 2026, and since then, the company has released an IOS XR hardening release that includes fixes for 111 IOS XR releases, some of which are rated 9.8 on the CVSS scale. The hardening release assigns one CVE to each Common Weakness Enumeration (CWE) bucket of fixed bugs and scores it at the most severe defect in that bucket.

    In addition to the Nexus 9000 switches, the vulnerability also affects other Cisco products, including the Nexus 3000 and 7000 lines, which are not affected by the vulnerability. However, the vulnerability does not affect the Nexus 9000 fabric switches running in Application Centric Infrastructure (ACI) mode.

    The vulnerability was first discovered by Sygnia, a cybersecurity firm, which reported that the China-nexus threat actor Fire Ant had been using this vulnerability to compromise IOS XR routers. The threat actor was found to be using the vulnerability to suppress syslog delivery, filter show command output, and support a hidden Generic Routing Encapsulation (GRE) tunnel.

    Cisco has stated that it is not aware of any malicious use of the flaw as of its September 2 disclosure. However, the company has warned that the window between disclosure and exploitation has effectively closed, and customers are advised to take immediate action to upgrade to a release that includes SMUs.

    The vulnerability is a serious concern for organizations that rely on Cisco's Nexus 9000 switches for their network infrastructure. The fact that unauthenticated remote attackers can execute code as root makes it a high-risk vulnerability that requires immediate attention.

    In response to the vulnerability, Cisco has released patches and an IOS XR hardening release that includes fixes for 111 IOS XR releases. However, due to the critical nature of the flaw, customers are advised to take immediate action to upgrade to a release that includes SMUs and apply them as soon as possible.

    The vulnerability highlights the importance of regular security testing and vulnerability management. It also emphasizes the need for organizations to stay up-to-date with the latest security patches and releases to protect themselves against known vulnerabilities.

    In conclusion, the critical Cisco Nexus 9000 flaw allows unauthenticated remote attackers to execute code as root, making it a serious concern for organizations that rely on these switches for their network infrastructure. Cisco has released patches and an IOS XR hardening release that includes fixes for 111 IOS XR releases, and customers are advised to take immediate action to upgrade to a release that includes SMUs and apply them as soon as possible.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Critical-Cisco-Nexus-9000-Flaw-Lets-Unauthenticated-Remote-Attackers-Run-Code-as-Root-A-Global-Security-Concern-ehn.shtml

  • https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html


  • Published: Thu Sep 3 12:20:18 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us