Cisco Warns Of Critical 9.8 CVE-2026-20212 In Nexus 9000 With Silicon One ASICs

Cisco has disclosed CVE-2026-20212, a critical 9.8-severity unauthenticated RCE in Nexus 9000 switches using its Silicon One ASICs — exposed on the default Layer 3 VRF via TCP ports 43210 and 43211.

Cisco Warns Of Critical 9.8 CVE-2026-20212 In Nexus 9000 With Silicon One ASICs

Cisco on September 2 disclosed CVE-2026-20212, a critical remote-code-execution flaw in Nexus 9000 Series switches equipped with its Silicon One ASICs — a bug the company scores 9.8 out of 10 and warns can be triggered by any unauthenticated attacker with network access to the device.

An unauthenticated 9.8, without a workaround

According to Cisco's advisory, the vulnerability lives in the Silicon One integration inside NX-OS. TCP ports 43210 and 43211 are exposed on the default Layer 3 VRF, so an attacker with routable access to a vulnerable Nexus switch can send crafted input and gain root code execution — the highest privilege on the device — or crash the S1HAL process and force a reboot, degrading a data-center fabric to a denial-of-service state.

Which Nexus 9000 models are hit

Cisco lists at least ten affected product identifiers, including N9K-C9804 and N9K-C9808 modular platforms as well as N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O/Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1 and N9336C-SE1. Nexus 9000 fabric switches running in ACI mode are unaffected, and Nexus 3000, Nexus 7000, MDS 9000, Firepower, Secure Firewall and UCS Fabric Interconnect models are on Cisco's confirmed "not vulnerable" list.

Cisco Nexus 9000 network switches - critical CVE-2026-20212 patch

What operators should do now

Cisco has shipped fixed NX-OS releases and is directing operators to its Software Checker. Until they can be scheduled, the advisory recommends infrastructure ACLs that block TCP traffic to ports 43210 and 43211 on management interfaces, plus a temporary Live Protect shield for CVE-2026-20212. Cisco PSIRT says it has no evidence of exploitation in the wild as of publication and that the flaw was found while resolving a TAC support case rather than in a red-team engagement.

An AI-cyber week that keeps getting worse

The Nexus 9000 disclosure lands in one of the noisiest weeks of the year for network and AI security, alongside the SonicWall SMA1000 RCE chain, Google's Gemini 3.8 Flash Cyber variant, CrowdStrike's SafeMind dual-model stack, and Anthropic and OpenAI's rival "AI red team" frontier deployments. For enterprise operators, the message is simple: patch the switch, then figure out where the AI defenders fit.

Reporting based on Cisco's PSIRT advisory, coverage from GBHackers, Cyberpress and Rapid7.

Category: Cyber Security

Tags: Cybersecurity CVE AI Chips AI Security

Related Articles