Security3 distinct publishers3 min readPublished Updated
CVE-2026-20212 needs no credentials and returns root on ten Silicon One Nexus 9000 models. Cisco named no fixed release with the advisory. Remediation starts with a web lookup and an access list.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The flaw traces to a default binding on an unrestricted IP address, which changes what remediation looks like compared with a memory-corruption bug. The service answers anything that can route to a switch address in the default Layer 3 VRF on either port [1]. Nothing authenticates, so crafted input goes straight to execution as root, and an attempt that fails takes down the S1HAL process and reloads the box [2]. The second outcome is the one that decides scan policy, because it means an unauthenticated probe can reload a device sitting in the data path.
The access list Cisco offers permits only required management and control-plane traffic, or explicitly denies TCP to a locally configured IP address on destination port 43210 or 43211, and Cisco says to prove it in a test environment first [6]. That is straightforward on a switch whose management addresses are already filtered. It is slower where the loopback or SVI is reachable from a broad internal range.
The temporary shield is narrower than it first reads. Live Protect lp00031 is supported on NX-OS 10.6(3), and on 10.6(3s) only through a second package covering the two Nexus Smart Switch identifiers. It does not support the Nexus 9804 or 9808, and it needs SSH, Telnet, or NX-API access to install [7]. Set that against the affected range: The Hacker News says the CVE Program record it checked on September 3 lists 45 NX-OS releases, 10.3(1) through 10.6(3s), as affected [8]. Only two of those 45 have a shield option, even counting 10.6(3s) generously, leaving the remaining 43 without coverage [2]. Two of the ten affected product identifiers are chassis with no shield at all [1].
The nearest thing to a fixed release in the published material is indirect. The shield's release notes say its operational mode transitions to N/A on upgrade to NX-OS 10.6(4) or higher [9]. That points at a target version, but the release note lacks the specificity of a fix table, and Cisco's advisory still routes release questions to the Software Checker [5].
Scope limits are worth stating plainly. Other Nexus 9000 models, Nexus 9000 fabric switches running in ACI mode, and the Nexus 3000 and 7000 lines are unaffected [10]. The check is show module against the ten listed identifiers [3].
The IOS XR half of the same disclosure is a separate job: seven umbrella CVEs, two of them at 9.8, affecting all releases regardless of device configuration, with no workaround for any version [11]. Cisco's route is to upgrade to a release carrying software maintenance updates and then apply them, roughly 16 per release, with 26.2.2 and 26.3.1 named as the first fixed releases needing none and anything outside the table going to a TAC case [13]. Russ Smoak, Cisco's vice president of information security, wrote in June that "the window between disclosure and exploitation has effectively closed" when he announced the twice-monthly model that groups internally found bugs into umbrella CVEs [12]. The XR7 (LNT) platforms, including the Cisco 8000 Series, NCS 1010, NCS 540L, and NCS 5700 Series, get one SMU that applies across all releases [15].
Ranked by verification strength, evidence, and original report placement.
CVE-2026-20212 (CVSS 9.8) in Cisco Nexus 9000 switches is a case of binding to an unrestricted IP address, leaving TCP ports 43210 and 43211 reachable in the default Layer 3 VRF instance; it affects 10 Silicon One-based Nexus 9000 switches.
An attacker who can reach a switch's address on either port can connect directly to the service; crafted input is executed as code with root privileges, and an exploitation attempt can also crash the S1HAL process and reload the device.
Cisco said it is not aware of any malicious use of the flaw as of its September 2 disclosure.
Cisco has published no fixed-release table for the Nexus 9000 flaw and directs customers to its Software Checker.
Cisco lists ten affected product identifiers in its Nexus 9000 advisory, checkable against the output of the show module command: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, N9K-C9808.
Cisco's stopgaps include an infrastructure access control list permitting only required management and control-plane traffic, or explicitly denying TCP packets to a locally configured IP address on destination port 43210 or 43211, proven in a test environment.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
1 article · September 3, 2026
2 articles · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Cisco and NVIDIA move the AI buying argument from GPU count to who owns the slowdown1 distinct publisher
product
Cisco and Nvidia go looking for the other third of AI spending1 distinct publisher
security
Cisco's IOS XR hardening guide puts every reversible router secret behind Type 61 distinct publisher
security
Eclypsium counted 1,051 AI-infrastructure vulnerabilities across 12 vendors in 38 days1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One advisory, checked once against the CVE record
Every technical fact in this story descends from a single Cisco advisory, and the three retellings agree on all of it: same CVE, same 9.8, same two ports in the default Layer 3 VRF, same S1HAL crash path, same ten product identifiers. The one step outside the vendor's own text is The Hacker News pulling the CVE Program record to recover the 45 affected NX-OS releases Cisco left to a web lookup. Nobody has tested the flaw independently, and no exploit code is described.
Mitigations outnumber fixes
Fixes reaching devices is the thinnest part of the record. Of the 45 NX-OS releases Cisco lists as affected, two have any Live Protect shield coverage and one of those only for the two Smart Switch identifiers; the 9804 and 9808 chassis have no shield path at all. On IOS XR, The Hacker News counted 14 of 111 affected releases with SMUs available on the day it checked, and the first release needing no SMUs, 26.2.2, has not shipped. What no source reports is uptake: nobody has counted exposed switches, and nobody has seen the flaw used.
Reported flatter than the remediation gap warrants
The coverage runs cooler than the underlying advisory. Two of the three write-ups treat this as routine patch Wednesday, Cisco's "no known malicious use" line travels with every version, and the headline verb everywhere is "patches" or "fixed." The part that stayed inside a bullet list is the one an operator would lead with: for most affected releases the practical answer today is a hand-written access list, because the shield covers two releases and the fixed image is a lookup rather than a version number.
Cisco scores its own bugs and sets the clock
One vendor supplied the severity score, the affected-product list, the affected-release list it then declined to print, the mitigations, and the calendar that decided when all of it appeared. The umbrella-CVE scheme compounds that: seven CVEs stand in for an undisclosed number of internally found IOS XR defects, each scored at its most severe member, so the count and the ceiling are both Cisco's arithmetic. Smoak's June framing gives the reason for the cadence, and it is also the vendor explaining why the vendor's own batching is safe.
Solid on mechanism, blind on exposure
The technical core survives three separate retellings without a contradiction, and one of those retellings verified Cisco's numbers against the CVE Program records instead of paraphrasing. What holds confidence down is everything only Cisco can see: how many switches carrying these ten identifiers are deployed or reachable, whether a fixed NX-OS image exists yet, and what the seven IOS XR umbrella CVEs actually contain.