SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026By Bapanapalli Prem Sai Siddhik

Summary

A critical flaw in Cisco Nexus 9000 Series Switches that use Silicon One ASICs can let an unauthenticated remote attacker run code with root privileges. The issue is tied to TCP ports 43210 and 43211 being reachable in the default Layer 3 VRF. An attacker who can reach those ports may send crafted input that runs as root, or trigger a crash of the S1HAL process that reloads the device. Fixed software and temporary workarounds are available.

Vulnerability Details

CVE ID CVSS Score EPSS Score Type
CVE-2026-20212 9.8 0.53% CWE-1327 : Binding to an Unrestricted IP Address

Technical Information

Critical Unauthenticated No User Interaction Network Access

CVE-2026-20212 — Silicon One Remote Code Execution

The flaw affects the Silicon One integration on certain Nexus 9000 switches. In the default Layer 3 VRF, TCP ports 43210 and 43211 are accessible. An unauthenticated attacker who can connect to either port can submit crafted input that is handled in a way that allows code execution with root privileges.

The same condition can also cause the S1HAL process to fail, which may reload the switch. No authentication and no user interaction are required, so any path that reaches these ports from a less-trusted network increases exposure.

Affected Products

The vulnerability applies to Cisco Nexus 9000 Series Switches that include a Silicon One ASIC. The following product identifiers (PIDs) were listed as affected:

  • N9324C-SE1U
  • N9348Y2C6D-SE1U
  • N9364E-SG2-O
  • N9364E-SG2-Q
  • N9396T12C-SE1
  • N9348Y12C-SE1
  • N9396Y12C-SE1
  • N9336C-SE1
  • N9K-C9804
  • N9K-C9808

Use the show module CLI command to confirm the device PID.

Impact

  • Root-level code execution
    A remote attacker with network access to ports 43210 or 43211 can run arbitrary code as root on the switch without credentials or user interaction.
  • Device reload
    Exploitation may crash the S1HAL process and force the switch to reload, interrupting traffic until the device recovers.

MITRE ATT&CK Mapping

Technique ID Technique Name Tactic
T1190 Exploit Public-Facing Application Initial Access
T1068 Exploitation for Privilege Escalation Privilege Escalation
T1499 Endpoint Denial of Service Impact

Mitigation and Recommendations

Fixed software releases address this issue. Upgrading is the full remediation path.

Fixed Software

Check the correct fixed release for each platform and software train with the Cisco Software Checker. Move affected systems to a release that includes the fix as soon as operationally possible.

Workarounds

If an upgrade cannot be applied right away, restrict access with infrastructure access control lists (iACLs). Allow only the management and control-plane traffic the device needs, or deny TCP traffic to locally configured IP addresses on ports 43210 and 43211.

A Live Protect shield for CVE-2026-20212 is available as a temporary mitigation for NX-OS Software. It is intended only as a bridge until a fixed release can be installed.

  • Confirm affected hardware with show module and match the PID to the list above.
  • Upgrade to a fixed software release.
  • Until then, apply the iACL workaround or the Live Protect shield.

Cisco PSIRT has stated it is not aware of public announcements or malicious use of this vulnerability. Even so, the combination of no authentication, no user interaction, and root-level execution makes prompt upgrade or mitigation important for any reachable affected switch.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

You can stage patches in a safe testing environment before production deployment and roll back if needed.

Experience the fastest and most accurate patching software here.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026