< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-03T21:22:07+05:30

Critical Cisco Nexus 9000 Vulnerability Allows Unauthenticated Remote Code Execution as Root

A critical vulnerability (CVE-2026-20212) in Cisco Nexus 9000 switches allows unauthenticated remote code execution as root via TCP ports 43210/43211, with patches and mitigations released. Cisco also issued an IOS XR hardening release addressing 7 CVEs, including two with CVSS 9.8 scores, affecting multiple network devices.

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.

The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

Read original article

*** END OF TRANSMISSION ***