importantSYS.SOURCE: The Hacker News• 2026-09-03T21:22:07+05:30
Critical Cisco Nexus 9000 Vulnerability Allows Unauthenticated Remote Code Execution as Root
A critical vulnerability (CVE-2026-20212) in Cisco Nexus 9000 switches allows unauthenticated remote code execution as root via TCP ports 43210/43211, with patches and mitigations released. Cisco also issued an IOS XR hardening release addressing 7 CVEs, including two with CVSS 9.8 scores, affecting multiple network devices.
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is
*** END OF TRANSMISSION ***