Back to advisories

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco released patches for CVE-2026-20212, a critical unauthenticated remote code execution vulnerability in Nexus 9000 switches (10 Silicon One-based models). Attackers can exploit this via TCP ports 43210 and 43211 to execute commands as root. If you run affected Nexus 9000 hardware, this is immediately exploitable.

CRITICALAdvisorySep 03, 2026
Action required
Identify all Nexus 9000 Silicon One-based switches in your environment and apply Cisco patches immediately. Monitor TCP 43210 and 43211 for suspicious traffic. Check logs for any connections to these ports from untrusted sources.
Affected products
Nexus 9000Cisco