Remote Code Execution Vulnerability in Cisco Nexus 9000 Series Switches
CVE-2026-20212

9.8CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
2 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20212?

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches permits unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability arises from the accessibility of TCP ports 43210 and 43211 within the default Layer 3 (L3) virtual routing and forwarding (VRF) instance. An exploit may enable attackers to connect to the device and send crafted input, impacting the S1HAL process and potentially leading to device instability and reboots.

Affected Version(s)

Cisco NX-OS Software 10.3(1)

Cisco NX-OS Software 10.3(2)

Cisco NX-OS Software 10.3(3)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.