Critical Cisco Nexus switch flaw lets unauthenticated attackers run code as root
Cisco patched a critical flaw in its Nexus 9000 data-center switches that lets an unauthenticated, remote attacker execute code as root. Tracked as CVE-2026-20212 and scored 9.8, the bug affects Nexus 9000 models built on Cisco's Silicon One chips and stems from a service that binds to an unrestricted address, leaving TCP ports 43210 and 43211 reachable in the default routing configuration. An attacker who can reach either port sends crafted input that runs with root privileges, and can also crash and reload the device. Cisco reported no known exploitation at disclosure and shipped fixed software, with an access-list workaround for those who cannot patch immediately.
- Check
- Identify Nexus 9000 switches using Silicon One chips, upgrade to fixed NX-OS releases, and until then apply the access-control-list workaround that blocks TCP ports 43210 and 43211 to the device.
- Affected
- Organizations running affected Cisco Nexus 9000 switches with Silicon One chips (CVE-2026-20212); a remote, unauthenticated attacker reaching the exposed ports can execute code as root or crash the device, no credentials needed.
- Fix
- Patch to fixed NX-OS software, apply the access-list workaround and temporary shield until then, restrict management-plane reachability to the switches, and monitor for unexpected connections to the affected ports.