Critical CVE-2026-20212 Vulnerability in Cisco Nexus 9000 Series Switches Allows Unauthenticated Remote Code Execution

Critical CVE-2026-20212 Vulnerability in Cisco Nexus 9000 Series Switches Allows Unauthenticated Remote Code Execution

Executive Summary

A critical vulnerability, CVE-2026-20212, has been identified in Cisco Nexus 9000 Series Switches equipped with Silicon One ASICs. This flaw enables unauthenticated, remote attackers to execute arbitrary code as root by sending crafted input to TCP ports 43210 or 43211, which are exposed by default in the Layer 3 VRF. Successful exploitation can result in full device compromise, network disruption, and potential lateral movement within enterprise or data center environments.

No exploitation in the wild or public proof-of-concept (PoC) has been confirmed as of September 4, 2026. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and there is no CISA-confirmed active exploitation. However, the exposure is automatable and the attack surface is well-documented, so urgent action is required.

Technical Information

CVE: CVE-2026-20212 CVSS: 9.8 (Critical) – AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CWE: 1327 (Binding to an Unrestricted IP Address) Vendor Advisory: Cisco Security Advisory Detection/Analysis: SOC Prime Analysis, The Hacker News

The vulnerability arises from the Silicon One integration exposing TCP ports 43210 and 43211 in the default Layer 3 VRF. An attacker with network access to these ports can send specially crafted input, which is executed as root on the device. Exploitation can also crash the S1HAL process, causing device reload and denial of service.

The attack requires no authentication or user interaction, making it highly accessible to threat actors. The impact includes full root compromise, configuration manipulation, traffic interception, service disruption, persistence, and lateral movement. Exploitation can also result in denial of service by crashing the S1HAL process.

Detection strategies include monitoring for unexpected inbound connections to TCP 43210 or 43211, Live Protect lp00031 hit events, %APPMGR-2-NXSECURE_CRIT_THREAT syslog messages, unexpected S1HAL process crashes or device reloads, unauthorized configuration changes, new or unusual processes on the switch, and unexpected outbound connections from the device. Snort Rule 67005 is available for detection.

Exploitation in the Wild

As of September 4, 2026, there are no confirmed reports of exploitation in the wild or public PoC for CVE-2026-20212. Both Cisco PSIRT and open-source threat intelligence sources confirm the absence of active exploitation. The vulnerability is not present in the CISA KEV catalog, and there is no CISA-confirmed exploitation.

The attack complexity is low, requiring only network access to the exposed ports. The potential impact is severe, including full device compromise and network disruption. The exposure is automatable, and the attack surface is well-documented, increasing the urgency for remediation.

APT Groups using this vulnerability

There is no direct evidence of APT or criminal exploitation of CVE-2026-20212 as of this report. However, recent activity by the Fire Ant group (China-nexus) has targeted Cisco IOS XR routers (not this vulnerability) for persistent implants and network manipulation, focusing on critical infrastructure. No evidence links Fire Ant or any other APT to CVE-2026-20212 at this time. (Sygnia Fire Ant Report)

Affected Product Versions

The affected products are Nexus 9000 Series Switches with Silicon One ASICs, specifically the following models: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808.

The affected NX-OS releases are versions 10.3(1) through 10.6(3s). For exact version information, consult the Cisco Software Checker.

Products not affected include other Nexus 9000 models, Nexus 9000 in ACI mode, Nexus 3000/7000, MDS 9000, Firepower, Secure Firewall, and UCS Fabric Interconnects.

Workaround and Mitigation

Permanent remediation requires upgrading to a fixed NX-OS release as identified by the Cisco Software Checker. Device PID should be checked with show module and confirmed against the affected list.

Temporary mitigations include restricting or blocking TCP 43210 and 43211 using iACLs to only required management/control-plane traffic, deploying Live Protect Shield lp00031 (supported on NX-OS 10.6(3) and 10.6(3s) for Smart Switches), and monitoring with show nxsecure policy status and show nxsecure log lp00031. Continuous monitoring for S1HAL instability, unauthorized changes, and syslog alerts is also recommended.

Indicators of Compromise

The following caveat applies: Indicators of Compromise (IOCs) are point-in-time and should be validated before enforcement. As of the time of writing, no public indicators of compromise were available for CVE-2026-20212.

References

Cisco Security Advisory, NVD CVE-2026-20212, The Hacker News Coverage, SOC Prime Analysis, Cisco Software Checker, Snort Rule 67005, Sygnia Fire Ant Report

Rescana is here for you

Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform, empowering organizations to continuously monitor, assess, and mitigate cyber risks across their supply chain and vendor ecosystem. Our platform delivers actionable intelligence and automated workflows to help you stay ahead of emerging threats. We are happy to answer any questions at info@rescana.com.