The record
Written from the 1 report below. Nothing here is unsourced.
- Cisco has released patches for a critical vulnerability in ten Silicon One-based Nexus 9000 switch models, tracked as CVE-2026-20212 with a severity score of 9.8.
- The Nexus flaw could allow a remote attacker without any credentials to run code with root privileges by sending crafted input to TCP ports 43210 or 43211.
- Cisco has also issued an IOS XR hardening release fixing seven umbrella CVEs, including two rated 9.8, that affect every IOS XR release and have no workarounds.
- Cisco has disclosed no fixed-release table for the Nexus issue, directing customers instead to its Software Checker and offering temporary mitigations such as an access control list and a Live Protect shield.
- Network operators running affected Nexus 9000 or IOS XR devices face urgent patching needs because the flaws allow full remote compromise of core networking equipment.
What to watch next
- Confirmation of fixed NX-OS releases for CVE-2026-20212, including the noted 10.6(4) release where the Live Protect shield becomes unnecessary.
- Any signs of exploitation of the Nexus flaw, which Cisco reported no malicious use of as of its September 2 disclosure.
- Availability of the remaining IOS XR SMUs, since only 14 of the 111 listed affected releases have SMUs available today.
Coverage1
1 report
English national1
All filed from IndiaSingle origin
Named China · Desk Phone 9800 · IOS XR · IP Phone 7800 · IP Phone 8800 · Nexus 9000 · Secure Email · Video Phone 8875 · Cisco · Fire Ant · Sygnia
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
