News

Nexus 9000 exposes root code execution ports

Louis Stowasser
Louis Stowasser
Tuesday 8 September 2026
Nexus 9000 exposes root code execution ports
Nexus 9000 exposes root code execution ports

CVE-2026-20212 is a remote-code-execution flaw in the Silicon One hardware-abstraction layer, or S1HAL, on a defined set of Cisco Nexus 9000 switches. These are not ordinary office access switches: they run Cisco NX-OS, the network operating system used to build high-speed data-centre fabrics, and are commonly operated by large enterprises, cloud and hosting providers, telecoms, hyperscalers, and teams running substantial on-premises or AI/GPU infrastructure.

The immediate concern is simple: an attacker does not need a switch account. If they can reach either vulnerable service over the network, Cisco says they can send crafted input that runs as root, the operating system’s most privileged account. That crosses the line from a network-exposed service bug to potential full control of a core piece of data-centre infrastructure.

Two listening ports create the path in

Cisco attributes CVE-2026-20212 to TCP ports 43210 and 43211 being reachable through the default Layer 3 virtual routing and forwarding instance (VRF). A VRF separates routing domains on the switch; here, the default one made the S1HAL services accessible where they should not have been. The underlying weakness is binding the service to an unrestricted IP address, rather than limiting which interfaces or networks can reach it.

Reachability is the one prerequisite. The vulnerable service need not be directly exposed to the public internet for this to matter: any compromised internal host, peered network, or improperly segmented management path that can contact those ports may be enough. A successful attempt can also crash S1HAL and reload the device, creating a denial-of-service outcome even where code execution is not achieved.

Cisco’s affected-product list and mitigation guidance limits exposure to Nexus 9000 models with specified Silicon One ASICs. It explicitly excludes other Nexus 9000 models, fabric switches in ACI mode, Nexus 7000, and—despite the broader CNA record title—Nexus 3000 systems. The affected NX-OS releases span the 10.3 through 10.6 trains; the CVE record lists them in detail.

Patch first; filter the ports now

Cisco has released fixed software, but its advisory does not provide a public, static first-fixed-release table for every platform and train. Teams should use Cisco Software Checker to select the appropriate image rather than infer a safe maintenance build. NX-OS 10.6(4) or later is confirmed fixed for the shield-supported 10.6 path; first-fixed releases for 10.3, 10.4, and 10.5 could not be independently confirmed from a public Cisco table.

Until upgrades are complete, apply infrastructure ACLs that allow only required management and control-plane traffic, or explicitly deny traffic to local switch addresses on TCP 43210 and 43211. Cisco Live Protect shield lp00031 is another temporary option for specified 10.6(3) devices, with separate notes for 10.6(3s); it does not support the affected N9K-C9804 or N9K-C9808.

No confirmed exploitation, despite noisy tracker claims

As of September 8, Cisco said it was not aware of malicious use or a public announcement, and no exploitation campaign has been confirmed. The flaw is not in CISA’s KEV catalogue as of that date. A repository named for the CVE has been labelled a PoC by some trackers, but direct inspection shows it is a generic “Draft or TODO” template, not exploit code; no genuine public proof of concept surfaced.

Inventory the specific hardware as well as NX-OS release, test the software upgrade, and remove network paths to those two ports. For teams that need this joined to the software they actually operate, SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203