Cisco Nexus 9000 CVE-2026-20212: unauthenticated root RCE on Silicon One models
Published 10 Sep 2026 · Severity: critical
Cisco has disclosed CVE-2026-20212, a critical vulnerability affecting specific Nexus 9000 switches that use Silicon One ASICs. An unauthenticated remote attacker able to reach TCP ports 43210 or 43211 in the default Layer 3 VRF could execute code with root privileges or crash the S1HAL process and reload the device. Cisco published fixes and a temporary Live Protect shield. Cisco PSIRT said it was not aware of public announcements or malicious use when the advisory was published. Organisations should identify the listed product IDs, restrict access to the affected ports, and upgrade using Cisco's release-specific guidance.