Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-20212

Unauthenticated RCE in Cisco Nexus 9000 Silicon One Switches

Unauthenticated remote code execution in ten Cisco Nexus 9000 Silicon One switches via a Silicon One integration flaw. CVSS 9.8. Patches released September 3, 2026.

cat cve-2026-20212.json
Vendor
Cisco
Product
Nexus 9000 Series Switches (Silicon One)
CVSS
9.8
EPSS (exploit probability)
0.5%
Status
patched
Published

CVE-2026-20212 is a critical unauthenticated remote code execution vulnerability in the Silicon One integration layer of Cisco Nexus 9000 Series Switches. An unauthenticated, remote attacker can exploit the flaw to execute arbitrary code with root privileges. No credentials required.

Ten Silicon One-based Nexus 9000 platform IDs are confirmed affected. The Cisco PSIRT advisory, published September 3, 2026, lists the specific affected models and the patched NX-OS software versions. No workaround is available; upgrading to a fixed NX-OS build is the documented remediation path.

Cisco has not confirmed active exploitation in the wild as of initial disclosure.