Cisco has warned that some of its Nexus 9000 data-centre switches can be taken over by anyone who can reach them over the network. The flaw, tracked as CVE-2026-20212 and scored 9.8 out of 10, lets an unauthenticated remote attacker run code as root on switches built around Cisco's Silicon One chip. Cisco published the advisory on 2 September, and Peru's national digital security centre (CNSD) relayed it to Latin American operators in its 3 September bulletin.
Root on a core switch is about as bad as a network flaw gets. These are the boxes that move traffic between servers inside a data centre, so an attacker with root on one is standing in the network's plumbing.
Two ports that should not be answering
According to Cisco, the problem is that TCP ports 43210 and 43211 are reachable in the switch's default Layer 3 virtual routing and forwarding instance (VRF), the routing instance a switch uses unless it is told otherwise. An attacker who can connect to either port can send crafted input that the device executes as code with root privileges. Cisco adds that exploitation can also crash the S1HAL process, which would make the switch reload and drop traffic.
The bug was not found by an outside researcher. Cisco says its engineers uncovered it while resolving a Technical Assistance Center (TAC) support case, and its Product Security Incident Response Team is not aware of any public announcements or malicious use of it.
Only Silicon One models, and only outside ACI mode
The flaw affects Nexus 9000 switches that include a Silicon One ASIC. At the time of publication Cisco lists ten product identifiers: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804 and N9K-C9808. Running show module on the switch shows its PID. Cisco has confirmed that other Nexus 9000 models, Nexus 9000 fabric switches running in ACI mode, the Nexus 3000 and 7000 lines, MDS 9000 switches, and its Firepower and Secure Firewall appliances are not affected.
It is Cisco's second critical networking advisory this week, after seven flaws across every IOS XR release, and it lands as state-linked crews keep turning Cisco gear into listening posts.
Block ports 43210 and 43211, then upgrade
Cisco has released fixed NX-OS software and points customers to its Software Checker to find the first fixed release for their platform. Until the upgrade is scheduled there are two stopgaps. The first is an infrastructure access control list (iACL) that allows only required management and control-plane traffic to the switch, or that explicitly denies TCP packets to any locally configured address on destination ports 43210 or 43211. Cisco says the workaround was proven in a test environment but asks customers to judge its impact in their own. The second is a Live Protect shield Cisco has published for CVE-2026-20212, which it describes as a temporary mitigation to bridge the gap until the update is installed.
The advisory carries Cisco bug ID CSCwu32817 and is version 1.0, marked final. Operators should treat the iACL as the thing to do today and the upgrade as the thing to do this month.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.