Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Executive Summary

Cisco released patches for a critical flaw (CVE-2026-20212, CVSS 9.8) affecting Silicon One-based Nexus 9000 switches. The vulnerability allows unauthenticated remote attackers to execute code with root privileges. An IOS XR hardening release bundles 7 umbrella CVEs, 2 rated 9.8, with no workaround for any IOS XR version.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-03T15:52:07+00:00 - Category: vulnerabilities

Original Description: Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

"If we are facing in the right direction, all we have to do is keep on walking."

— Unknown
Source: The Hacker News