Cisco Nexus 9000 switches hit by critical unauthenticated root RCE flaw, CVSS 9.8

Cisco disclosed a critical vulnerability on September 2, 2026 affecting 10 Silicon One-based Nexus 9000 series switches that lets unauthenticated remote attackers execute arbitrary code with root privileges. The flaw, tracked as CVE-2026-20212, carries a CVSS score of 9.8 out of 10 — the maximum severity Cisco assigns to remotely exploitable issues, as first reported by The Hacker News.
How the Flaw Works
The vulnerability stems from a service binding to an unrestricted IP address, which leaves TCP ports 43210 and 43211 reachable within the default Layer 3 virtual routing and forwarding (VRF) instance. Any attacker who can reach a switch on either port can connect directly to the exposed service. Crafted input sent to that service is then executed as code with root privileges — no authentication or prior access required. A failed or partial exploitation attempt can also crash the switch’s S1HAL process and force a device reload, making the flaw dangerous even in denial-of-service scenarios.
Why This Matters for AI Infrastructure
Nexus 9000 Silicon One switches sit at the core of many modern data center fabrics, including networks built to support large-scale AI training and inference clusters. A root-level compromise at the switch layer gives an attacker a foothold that can intercept, redirect, or disrupt traffic across an entire data center — a far more consequential blast radius than a typical server-side bug. Cisco said it is not aware of any malicious exploitation as of its disclosure date.
Patch Status and Mitigations
Cisco has not yet published a complete fixed-release table. The company is directing customers to its Software Checker tool to determine exposure, and recommends two interim mitigations: deploying an infrastructure access control list (iACL) to block the two exposed ports, and enabling Cisco’s temporary “Live Protect” shield. Cisco indicated that approximately 16 Software Maintenance Upgrades (SMUs) will be available across affected release trains, with versions 26.2.2 and 26.3.1 planned as the first fully-fixed releases that won’t require a separate SMU.
What Network Operators Should Do Now
Given the CVSS 9.8 rating and the lack of authentication required, security teams running Nexus 9000 Silicon One switches should treat this as an emergency patching priority. Until a permanent fix is available, applying the iACL mitigation and enabling Live Protect are not optional hardening steps — they are the only defense against a flaw that can hand an attacker root access to core data center switching infrastructure with a single crafted packet.
Originally reported by The Hacker News. Read the original article for additional details.
View original source