Cisco Nexus 9000 unrestricted IP binding RCE (CVE-2026-20212)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-20212 exposes Cisco Nexus 9000 switches to unauthenticated remote code execution through unrestricted IP binding on TCP 43210 and 43211. The flaw leaves those ports reachable in the default Layer 3 VRF instance, and crafted input can run as root or crash the S1HAL process and reload the device. Cisco said it was not aware of malicious use as of the September 2 disclosure. The affected scope includes 10 Silicon One-based Nexus 9000 PIDs and 45 NX-OS releases listed through Cisco's Software Checker.
Timeline
-
03.09.2026 18:52 2 articles · 3h ago
Cisco discloses CVE-2026-20212 in Nexus 9000 switches
Initial DisclosureCisco disclosed CVE-2026-20212, a critical NX-OS flaw affecting 10 Silicon One-based Nexus 9000 switches and 45 NX-OS releases from 10.3(1) through 10.6(3s), where unrestricted IP binding leaves TCP ports 43210 and 43211 reachable in the default Layer 3 VRF and crafted input can execute as root or crash the S1HAL process and reload the device. Cisco said it was not aware of malicious use as of the September 2 disclosure and directed customers to its Software Checker, an iACL that blocks the two ports, and the temporary Live Protect shield lp00031 as stopgaps.
Show sources
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root — thehackernews.com — 03.09.2026 18:52
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root — thehackernews.com — 03.09.2026 18:52