Cisco has released security updates for a critical vulnerability affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
The company has also issued an IOS XR hardening release covering seven umbrella CVEs, including two vulnerabilities rated CVSS 9.8. Cisco said there is currently no workaround available for affected IOS XR versions.
Critical Nexus 9000 Vulnerability Enables Root-Level Code Execution
The Nexus 9000 vulnerability is tracked as CVE-2026-20212 and carries a CVSS score of 9.8.
The flaw is caused by a service binding to an unrestricted IP address, leaving TCP ports 43210 and 43211 accessible through the default Layer 3 virtual routing and forwarding (VRF) instance.
An attacker who can reach a vulnerable switch on either port could connect directly to the exposed service. By sending specially crafted input, the attacker could potentially execute arbitrary code with root-level privileges.
Cisco warned that exploitation attempts could also cause the S1HAL process to crash, potentially resulting in a device reload and disruption of network operations.
As of its September 2 disclosure, Cisco said it was not aware of malicious exploitation of the vulnerability.
10 Nexus 9000 Models Are Affected
Cisco has identified the following product IDs as affected:
- N9324C-SE1U (Nexus Smart Switch)
- N9348Y2C6D-SE1U (Nexus Smart Switch)
- N9364E-SG2-O
- N9364E-SG2-Q
- N9396T12C-SE1
- N9348Y12C-SE1
- N9396Y12C-SE1
- N9336C-SE1
- N9K-C9804
- N9K-C9808
The vulnerability does not affect other Nexus 9000 models, Nexus 9000 fabric switches operating in Application Centric Infrastructure (ACI) mode, or the Nexus 3000 and Nexus 7000 product families.
According to the CVE Program record reviewed on September 3, Cisco lists 45 NX-OS releases, ranging from 10.3(1) through 10.6(3s), as affected.
Cisco recommends customers use its Software Checker to determine the appropriate fixed release for their specific device and software version.
Cisco Recommends Access Controls and Live Protect
Until a fixed release can be deployed, Cisco recommends using an infrastructure access control list (iACL) to restrict access to the affected ports.
Organizations can explicitly deny TCP traffic destined for a locally configured IP address on ports 43210 and 43211, although Cisco recommends testing the configuration before deployment.
Cisco has also provided a temporary Live Protect shield, LP00031, as an additional mitigation.
The shield is supported on NX-OS 10.6(3) and, through a separate shield package, on 10.6(3s) for the two affected Smart Switch models. It is not supported on the Nexus 9804 or 9808 and requires SSH, Telnet, or NX-API access.
Cisco notes that the shield’s operational mode changes to N/A after upgrading to NX-OS 10.6(4) or later.
IOS XR Hardening Release Addresses Seven CVEs
Alongside the Nexus fixes, Cisco released an IOS XR hardening update covering seven umbrella vulnerabilities.
Under Cisco’s risk-based disclosure model, multiple internally discovered security bugs are grouped according to their Common Weakness Enumeration (CWE) category. Each umbrella CVE receives a severity score based on the most serious vulnerability included in that group.
Two of the seven CVEs have a maximum severity rating of 9.8:
- CVE-2026-20274 — Covers memory-safety and resource-lifetime issues.
- CVE-2026-20279 — Covers access-control vulnerabilities, including missing authentication for critical functions and improper certificate validation.
The remaining five vulnerabilities are:
- CVE-2026-20275
- CVE-2026-20276
- CVE-2026-20277
- CVE-2026-20278
- CVE-2026-20280
These vulnerabilities have maximum CVSS scores ranging from 8.2 to 8.8.
Cisco said the IOS XR vulnerabilities affect all releases regardless of device configuration.
IOS XR Customers Must Apply SMUs
For customers running IOS XR7 (LNT) platforms, including Cisco 8000 Series, NCS 1010, NCS 540L, and NCS 5700 Series devices, Cisco has provided a dedicated Software Maintenance Update (SMU) that applies across all releases.
Cisco said approximately 16 SMUs may be available for each release. Future IOS XR versions 26.2.2 and 26.3.1 are expected to be the first fixed releases that will not require these SMUs.
Customers running a release outside Cisco’s published table are advised to open a Technical Assistance Center (TAC) case.
SMUs are currently available for:
- 6.9.2
- 7.3.2
- 7.9.2
- 7.9.21
- 7.10.2
- 7.11.2
- 7.11.21
- 24.2.2
- 24.2.21
- 24.4.2
- 25.2.21
- 25.4.1
- 25.4.2
- 26.1.2
- 26.2.1
SMUs for 24.1.2, 24.3.2, 25.1.2, and 25.2.2 are listed as future releases.
Multiple IOS XR Components Require Updates
Cisco’s advisory identifies fixes across several IOS XR functional areas, including:
- BGP
- Crypto IKE
- gRPC
- IP-SLA
- IS-IS
- MPLS and MPLS-TE
- Multicast
- OSPF
- Segment Routing
- TCP Authentication Option
- Zero Touch Provisioning (ZTP)
Among the listed fixes are CSCwv19790 for all XR7 LNT platforms, CSCwv19170 for crypto-ike, CSCwt41683 for gRPC, and CSCwu36622 for ZTP.
Cisco also noted that CSCwv19171 applies to both IS-IS and OSPF.
Cisco’s New Disclosure Model
The September 2 security release represents the third scheduled IOS XR hardening release in 30 days.
It follows Cisco’s first hardening release on August 5, which addressed IOS XE and Catalyst SD-WAN vulnerabilities. Two weeks later, Cisco disclosed additional security issues affecting Crosswork and Secure Workload, including two vulnerabilities rated CVSS 10.0.
Cisco introduced its twice-monthly disclosure model to group internally discovered vulnerabilities into broader umbrella CVEs.
However, Russ Smoak, Cisco’s vice president of information security, previously warned that the period between vulnerability disclosure and potential exploitation has effectively become very short.
Cisco Also Fixes Secure Email and Phone Vulnerabilities
Cisco’s latest security updates also address vulnerabilities in other products.
Two publicly disclosed S/MIME decryption vulnerabilities, tracked as CVE-2026-20354 and CVE-2026-20355, carry CVSS scores of 5.9. The flaws could allow a machine-in-the-middle attacker to recover plaintext from email traffic passing between gateways running AsyncOS 16.5.0 or earlier with S/MIME enabled.
Cisco said fixed releases for these vulnerabilities are identified in the corresponding bug records.
The company also fixed a denial-of-service vulnerability, CVE-2026-20281, rated CVSS 7.5, affecting certain Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 devices.
The issue affects devices registered with Unified Communications Manager when Web Access is enabled, although Cisco says that setting is disabled by default.
Depending on the affected model, fixes are available in SIP Software 5.0(1), 14.4(1)SR3, 14.4(1)SR4, or 11.0(6)SR8.
Cisco Router Security Comes Under Increased Scrutiny
The latest Cisco security updates arrive shortly after cybersecurity firm Sygnia reported activity by a China-linked threat actor known as Fire Ant.
According to Sygnia, the group deployed custom implants on IOS XR routers that could suppress syslog messages, manipulate the output of show commands, and establish a hidden Generic Routing Encapsulation (GRE) tunnel.
The implants were also reportedly used to capture network packets, transfer them to external FTP servers, and perform connection attempts and port scans against systems connected to critical infrastructure.
Sygnia said its investigation began after researchers discovered an active tunnel interface on a router despite finding no corresponding configuration or commit history.
The discrepancy raised concerns that the router’s operational state could no longer be trusted to accurately reflect its configuration and audit records.
Sygnia did not identify the initial access method used by the threat actor and did not attribute the activity to any specific vulnerability.
Organizations Should Prioritize Cisco Patches
The critical CVE-2026-20212 vulnerability deserves particular attention because successful exploitation could provide an unauthenticated remote attacker with root-level code execution on affected Nexus 9000 switches.
Administrators should check their Nexus 9000 and IOS XR deployments against Cisco’s security advisories and Software Checker, install the appropriate fixed releases or SMUs, and apply the recommended network-level protections where immediate patching is not possible.
With threat actors increasingly targeting network infrastructure, keeping routers and switches patched is essential to preventing attackers from gaining persistent access to critical environments.
