Critical Cisco Nexus 9000 Series Switch Flaw Allows Unauthenticated Remote Code Execution
A critical vulnerability (CVE-2026-20212) in Cisco Nexus 9000 Series Switches with Silicon One ASICs allows unauthenticated remote attackers to execute arbitrary code with root privileges.

Cisco has disclosed a critical vulnerability affecting its Nexus 9000 Series Switches that utilize Silicon One ASICs. Tracked as CVE-2026-20212, the flaw carries a CVSS score of 9.8 out of 10 and could permit an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected devices.
The vulnerability, identified as CWE-1327, was discovered by Cisco's Product Security Incident Response Team (PSIRT) while investigating a Technical Assistance Center support case. Although Cisco stated it was not aware of any public exploitation or malicious activity involving the flaw at the time of disclosure, the severity of the vulnerability warrants immediate attention from network administrators.
The root cause of the issue lies in the exposure of TCP ports 43210 and 43211. These ports are reachable through the default Layer 3 virtual routing and forwarding (VRF) configuration on vulnerable devices. Crucially, an attacker does not need any valid credentials to exploit this vulnerability. By connecting to an exposed switch and sending specially crafted input to these ports, an attacker can achieve code execution with root-level privileges.
Successful exploitation grants an attacker extensive control over the targeted switch. This level of access could be leveraged to modify network configurations, intercept sensitive data, disrupt network services, or pivot to other systems within the network. Cisco also warned that the vulnerability could lead to a crash of the S1HAL process, potentially causing the affected device to reload and resulting in a network outage.
The vulnerability specifically impacts Cisco Nexus 9000 Series Switches equipped with a Silicon One ASIC. Cisco has provided a list of affected product identifiers, including models such as N9324C-SE1U, N9348Y2C6D-SE1U, and N9K-C9808, among others. Administrators can verify the installed module and product identifier by executing the show module command on their switches and comparing the output against Cisco's advisory.
Cisco has confirmed that other Nexus 9000 models not listed in the advisory, as well as Nexus 9000 Fabric Switches operating in ACI mode, are not affected. Additionally, Nexus 3000 and 7000 Series Switches, MDS 9000 Series Multilayer Switches, and various Cisco security appliances and UCS platforms are also unaffected by this specific vulnerability.
To address CVE-2026-20212, Cisco has released software updates. The company strongly recommends that organizations upgrade to a fixed NX-OS release as soon as possible. As a temporary mitigation measure until patching can be completed, administrators can implement infrastructure access control lists (iACLs) to restrict management and control-plane traffic to only necessary sources. Further mitigation involves configuring iACLs to explicitly deny TCP traffic destined for ports 43210 and 43211 on locally configured switch IP addresses.
Cisco has also made a Live Protect shield available as a temporary protective measure. However, this shield is intended solely as a stopgap until a full software upgrade can be deployed, emphasizing the critical need for patching to fully remediate the risk posed by this severe vulnerability.