Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has issued urgent fixes for a critical Nexus 9000 flaw, CVE-2026-20212, that could let a remote unauthenticated attacker run code as root on affected Silicon One-based switches. The company also released an IOS XR hardening update covering seven umbrella CVEs, while separate advisories address Secure Email S/MIME decryption issues, a Desk Phone denial-of-service bug, and concerns tied to Fire Ant activity on IOS XR routers. #Cisco #CVE-2026-20212 #IOSXR #FireAnt

Keypoints

  • CVE-2026-20212 affects 10 Nexus 9000 Silicon One-based switch models.
  • The flaw can allow remote code execution as root through TCP ports 43210 and 43211.
  • Cisco says no active exploitation is known and offers iACL and Live Protect mitigations.
  • The IOS XR hardening release bundles seven CVEs, including two rated 9.8.
  • Fire Ant was previously seen using implants on IOS XR routers to hide activity and tunnel traffic.

Read More: https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html