Security1 distinct publisher3 min readPublished
CVE-2026-20212 needs no credentials and returns root on ten Silicon One Nexus 9000 models. Cisco named no fixed release with the advisory. Remediation starts with a web lookup and an access list.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The flaw traces to a default binding on an unrestricted IP address, which changes what remediation looks like compared with a memory-corruption bug. The service answers anything that can route to a switch address in the default Layer 3 VRF on either port [1]. Nothing authenticates, so crafted input goes straight to execution as root, and an attempt that fails takes down the S1HAL process and reloads the box [2]. The second outcome is the one that decides scan policy, because it means an unauthenticated probe can reload a device sitting in the data path.
The access list Cisco offers permits only required management and control-plane traffic, or explicitly denies TCP to a locally configured IP address on destination port 43210 or 43211, and Cisco says to prove it in a test environment first [6]. That is straightforward on a switch whose management addresses are already filtered. It is slower where the loopback or SVI is reachable from a broad internal range.
The temporary shield is narrower than it first reads. Live Protect lp00031 is supported on NX-OS 10.6(3), and on 10.6(3s) only through a second package covering the two Nexus Smart Switch identifiers. It does not support the Nexus 9804 or 9808, and it needs SSH, Telnet, or NX-API access to install [7]. Set that against the affected range: The Hacker News says the CVE Program record it checked on September 3 lists 45 NX-OS releases, 10.3(1) through 10.6(3s), as affected [8]. Only two of those 45 have a shield option, even counting 10.6(3s) generously, leaving the remaining 43 without coverage [2]. Two of the ten affected product identifiers are chassis with no shield at all [1].
The nearest thing to a fixed release in the published material is indirect. The shield's release notes say its operational mode transitions to N/A on upgrade to NX-OS 10.6(4) or higher [9]. That points at a target version, but the release note lacks the specificity of a fix table, and Cisco's advisory still routes release questions to the Software Checker [5].
Scope limits are worth stating plainly. Other Nexus 9000 models, Nexus 9000 fabric switches running in ACI mode, and the Nexus 3000 and 7000 lines are unaffected [10]. The check is show module against the ten listed identifiers [3].
The IOS XR half of the same disclosure is a separate job: seven umbrella CVEs, two of them at 9.8, affecting all releases regardless of device configuration, with no workaround for any version [11]. Cisco's route is to upgrade to a release carrying software maintenance updates and then apply them, roughly 16 per release, with 26.2.2 and 26.3.1 named as the first fixed releases needing none and anything outside the table going to a TAC case [13]. Russ Smoak, Cisco's vice president of information security, wrote in June that "the window between disclosure and exploitation has effectively closed" when he announced the twice-monthly model that groups internally found bugs into umbrella CVEs [12]. The XR7 (LNT) platforms, including the Cisco 8000 Series, NCS 1010, NCS 540L, and NCS 5700 Series, get one SMU that applies across all releases [15].
Ranked by verification strength, evidence, and original report placement.
Cisco has published no fixed-release table for the Nexus 9000 flaw and directs customers to its Software Checker.
CVE-2026-20212 (CVSS 9.8) in Cisco Nexus 9000 switches is a case of binding to an unrestricted IP address, leaving TCP ports 43210 and 43211 reachable in the default Layer 3 VRF instance; it affects 10 Silicon One-based Nexus 9000 switches.
An attacker who can reach a switch's address on either port can connect directly to the service; crafted input is executed as code with root privileges, and an exploitation attempt can also crash the S1HAL process and reload the device.
Cisco lists ten affected product identifiers in its Nexus 9000 advisory, checkable against the output of the show module command: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, N9K-C9808.
Cisco said it is not aware of any malicious use of the flaw as of its September 2 disclosure.
Cisco's stopgaps include an infrastructure access control list permitting only required management and control-plane traffic, or explicitly denying TCP packets to a locally configured IP address on destination port 43210 or 43211, proven in a test environment.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Cisco and NVIDIA move the AI buying argument from GPU count to who owns the slowdown1 distinct publisher
product
Cisco and Nvidia go looking for the other third of AI spending1 distinct publisher
security
Cisco's IOS XR hardening guide puts every reversible router secret behind Type 61 distinct publisher
security
Eclypsium counted 1,051 AI-infrastructure vulnerabilities across 12 vendors in 38 days1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Precise numbers, one set of books
The ten product identifiers, the CVSS ceilings, the dozens of SMU identifiers broken out by routing protocol — all of it comes from two Cisco advisories. What lifts this above stenography is that The Hacker News went to the CVE Program records on September 3 and recovered the affected NX-OS range, 45 releases from 10.3(1) to 10.6(3s), that the advisory itself declines to print. Nobody has tested the listener, no proof-of-concept appears, and the only statement about exploitation is Cisco's own.
Nobody has counted the exposed switches
For a flaw whose only precondition is reachability, the number that matters is how many of these switches answer on 43210 or 43211 — and no figure like it appears anywhere in this reporting. There is no install-base estimate, no scan data, no patch-uptake signal, and for the Nexus side not even a fixed release to adopt. The closest thing to an uptake measure is the count of IOS XR releases with maintenance updates actually shipped, which describes vendor readiness rather than customer action.
Severity is vendor-graded; the fix is thinner than the lead suggests
The headline promise — unauthenticated remote root — is real on its face but entirely Cisco's grading, with no observed abuse and no independent test behind it. Pulling the other way, the piece opens by saying patches have been released and then concedes no fixed release has been named for the Nexus switches, while the shield that reads as a mitigation covers two of 45 affected releases and eight of ten models. The severity framing runs slightly ahead of the evidence; the remediation framing runs slightly ahead of what customers can actually install.
Cisco finds the bugs, buckets them, and grades them
Since June, Cisco has published on a twice-monthly schedule that folds its own internally found defects into umbrella CVEs, each scored at the most severe bug in its bucket. That is a defensible engineering process and also a presentation choice: seven identifiers stand in for an unstated number of fixes, and the affected-version list for the Nexus flaw lives behind a vendor web tool instead of in the advisory. Russ Smoak's line about the disclosure-to-exploitation window closing is the justification offered for both. The reporting relays this architecture without probing it.
Confident on the what, blind on the how much
The technical detail is checkable — a reader with a Nexus chassis can settle their own exposure in one command, and the CVE records back the version range. What we cannot stand behind is scale or urgency: one publisher, no independent testing, no exposure data, and no second opinion on whether Cisco's umbrella scoring reflects what was actually fixed.