Remote Code Execution Vulnerability in Cisco Nexus 9000 Series Switches
CVE-2026-20212

9.8CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
2 September 2026

Badges

πŸ“ˆ TrendedπŸ“ˆ Score: 3,870πŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2026-20212?

CVE-2026-20212 is a critical vulnerability affecting the Cisco Nexus 9000 Series Switches, specifically linked to the integration of Silicon One technology. This vulnerability permits unauthenticated remote attackers to leverage accessible TCP ports (43210 and 43211) within the default Layer 3 virtual routing and forwarding (VRF) configuration. By exploiting this flaw, attackers can execute arbitrary code with root privileges on the affected devices. The implications of this vulnerability are significant: unauthorized access to switch functionality can lead to a broad range of security breaches and operational disruptions within an organization's network infrastructure.

Technical details indicate that successful exploitation could not only allow code execution but may also destabilize the S1HAL process, causing the switch to crash and necessitating a device reload. Such conditions can severely impair network reliability and lead to service interruptions essential for organizational operations.

Potential impact of CVE-2026-20212

  1. Unauthorized Control: The most concerning impact is the potential for attackers to gain unauthorized control over crucial network infrastructure, enabling them to manipulate traffic, intercept data, and affect overall network performance.

  2. Service Disruption: The vulnerability may lead to crashes of the S1HAL process, causing unexpected device reboots. This instability can disrupt network services, resulting in significant downtime and affecting business continuity.

  3. Data Integrity Risk: With remote code execution capabilities, attackers could perform malicious activities that compromise data integrity, including data exfiltration or the insertion of harmful code, leading to severe security incidents.

Affected Version(s)

Cisco NX-OS Software 10.3(1)

Cisco NX-OS Software 10.3(2)

Cisco NX-OS Software 10.3(3)

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Critical Cisco Nexus 9000 Flaw Allows Remote Root Code Execution | eSecurity Planet

Cisco disclosed a critical Nexus 9000 flaw that can allow unauthenticated remote attackers to execute code as root on affected switches. Cisco patches CVE-2026-20212, a critical Nexus 9000 flaw that can let unauthenticated remote attackers execute code as root.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ“ˆ

    Vulnerability started trending

  • πŸ“°

    First article discovered by Esecurity Planet

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.