Skip to content
feed: live
>_0dayNews
cisco
● Breaking

Cisco Patches Critical RCE in Nexus 9000 Switches

Cisco has patched a CVSS 9.8 flaw in ten Silicon One Nexus 9000 switches letting unauthenticated remote attackers execute arbitrary code as root. No workaround available.

Cisco Patches Critical RCE in Nexus 9000 Switches
Photo: Unknown / Wikimedia Commons · CC BY 2.5
airgapMorgan "airgap" Reyes·Published ·1 min read

Cisco has released patches for a critical remote code execution flaw in ten Nexus 9000 Series switches. CVE-2026-20212, CVSS 9.8, per the Cisco PSIRT advisory published September 3, 2026.

The flaw is in the Silicon One integration layer. An unauthenticated, remote attacker can exploit it to execute code with root privileges on affected devices. No credentials required. Confirmed per Cisco’s advisory.

Ten Nexus 9000 platform IDs are affected. The advisory lists the specific models and corresponding patched NX-OS software versions. No workaround is documented; upgrading to a fixed NX-OS build is the only remediation path.

Cisco has not confirmed active exploitation as of advisory publication. Unconfirmed: whether in-the-wild activity has emerged since. The Cisco infrastructure disclosure pattern at this severity is consistent: the August ASA/FTD VPN flaw and July FMC hard-coded credential both landed in CISA’s Known Exploited Vulnerabilities catalog shortly after disclosure. Analysis: KEV addition would be consistent with that pattern if exploitation is confirmed.

Full affected platform list, fixed NX-OS versions, and upgrade targets are in Cisco’s security advisory.

Related CVEs
  • [ CRITICAL ]CVE-2026-20212Unauthenticated RCE in Cisco Nexus 9000 Silicon One Switches

Found this useful? Share it.