Cisco has issued urgent fixes for a critical Nexus 9000 flaw, CVE-2026-20212, that could let a remote unauthenticated attacker run code as root on affected Silicon One-based switches. The company also released an IOS XR hardening update covering seven umbrella CVEs, while separate advisories address Secure Email S/MIME decryption issues, a Desk Phone denial-of-service bug, and concerns tied to Fire Ant activity on IOS XR routers. #Cisco #CVE-2026-20212 #IOSXR #FireAnt
Keypoints
- CVE-2026-20212 affects 10 Nexus 9000 Silicon One-based switch models.
- The flaw can allow remote code execution as root through TCP ports 43210 and 43211.
- Cisco says no active exploitation is known and offers iACL and Live Protect mitigations.
- The IOS XR hardening release bundles seven CVEs, including two rated 9.8.
- Fire Ant was previously seen using implants on IOS XR routers to hide activity and tunnel traffic.
Read More: https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html