CVE Tools

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker NewsBy The Hacker News

PatchCisco Nexus 9000Cisco IOS XR

Our summary

Cisco has issued updates for a critical vulnerability, identified as CVE-2026-20212 with a CVSS score of 9.8, affecting ten models of Silicon One-based Nexus 9000 switches. This defect allows unauthenticated remote attackers to achieve root-level code execution by sending crafted input to exposed TCP ports 43210 and 43211 within the default Layer 3 VRF instance. Alongside this specific fix, Cisco released an IOS XR hardening update addressing seven umbrella CVEs, two of which carry a maximum severity rating of 9.8, impacting all versions without available workarounds.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store