Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cisco Nexus 9000 NX-OS patch release for CVE-2026-20212

Security Patch Release
First reported
Last updated
Happening score
H score 14
1 unique sources, 1 articles

Summary

Hide ▲

Cisco released NX-OS patches for CVE-2026-20212, a critical flaw affecting 10 Silicon One-based Nexus 9000 switch PIDs. The bug lets an unauthenticated remote attacker reach TCP 43210/43211 and run code as root on exposed devices. Cisco also provided temporary mitigations — an iACL and a Live Protect shield — while customers use the Software Checker to find fixed releases.

Related Happenings

Cisco IOS XR hardening release (umbrella CVEs)

Security Patch Release
H score14 First: 03.09.2026 18:52 Last: 03.09.2026 18:52 Sources 1

How related: Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.

About this happening: Cisco released an IOS XR hardening update that covers all IOS XR releases, including XR7 (LNT), and bundles 7 umbrella CVEs. Two of the grouped flaws are rated 9...

Cisco security patch release for CVE-2026-20337

Security Patch Release
H score30 First: 11.08.2026 14:03 Last: 11.08.2026 14:03 Sources 1

About this happening: Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...

Google security patch release for CVE-2025-48595

Security Patch Release
H score45 First: 02.06.2026 14:10 Last: 02.06.2026 14:10 Sources 1

About this happening: Google's June 2026 Android security patches address 124 vulnerabilities, including an actively exploited zero-day. The release ships as the 2026-06-01 and 2026-0...

Cisco Secure Workload REST API patch release (CVE-2026-20223)

Security Patch Release
H score55 First: 22.05.2026 08:36 Last: 22.05.2026 08:36 Sources 1

About this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...

Cisco ThousandEyes and Nexus security patches

Security Patch Release
H score31 First: 21.05.2026 15:04 Last: 21.05.2026 15:04 Sources 1

About this happening: Cisco released patches for three medium-severity vulnerabilities affecting ThousandEyes Virtual Appliance, ThousandEyes Enterprise Agent, and Nexus 3000/9000 switche...

Timeline

  1. 03.09.2026 18:52 2 articles · 3h ago

    Cisco releases NX-OS patches for CVE-2026-20212

    Initial Disclosure

    Cisco released patches for CVE-2026-20212 affecting 10 Silicon One-based Nexus 9000 switch PIDs after identifying an unrestricted-bind condition that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 VRF; an unauthenticated remote attacker who reaches either port can execute code as root, and an exploitation attempt can also crash the S1HAL process and reload the device.

    Show sources
  2. 03.09.2026 18:52 1 articles · 3h ago

    Cisco lists affected NX-OS releases and temporary mitigations

    Technical Analysis Update

    Cisco lists 45 NX-OS releases, from 10.3(1) through 10.6(3s), as affected and points customers to the Software Checker for fixed-release selection; until a fixed build is confirmed, Cisco recommends an infrastructure access control list blocking TCP 43210 and 43211 or Live Protect shield lp00031 where supported.

    Show sources