Exploits

Cisco Nexus CVE-2026-20212 Critical RCE Vulnerability

Published  ·  7 min read

Cisco Nexus

Cisco just dropped patches for a critical security flaw affecting 10 of its Nexus 9000 switches. The vulnerability, tracked as CVE-2026-20212, allows attackers to execute code as root on affected devices. No authentication required. No credentials needed.

At the same time, Cisco released an IOS XR hardening update that bundles seven umbrella CVEs. Two of them are rated 9.8 on the CVSS scale.

Let me break down what's happening and what you need to do.

Quick Summary

What

Details

Vulnerability

CVE-2026-20212

CVSS Score

9.8 (Critical)

Affected

10 Nexus 9000 switches

Impact

Root RCE, device reload

Patch

Available via Software Checker

Workarounds

iACL, Live Protect shield

The Nexus Vulnerability

What's the Problem?

The flaw leaves TCP ports 43210 and 43211 exposed in the default Layer 3 VRF instance. An attacker who can reach a switch's address on either port can connect directly. Once connected, they send crafted input that gets executed as code with root privileges.

The Impact:

  • Remote code execution as root
  • Device crash and reload
  • Full compromise of the switch

The Good News:

Cisco said it's not aware of any malicious use of the flaw as of its September 2 disclosure. But that doesn't mean you should wait.

Affected Nexus 9000 Models

Here are the 10 models that are vulnerable:

PID

Model

N9324C-SE1U

Nexus Smart Switch

N9348Y2C6D-SE1U

Nexus Smart Switch

N9364E-SG2-O

—

N9364E-SG2-Q

—

N9396T12C-SE1

—

N9348Y12C-SE1

—

N9396Y12C-SE1

—

N9336C-SE1

—

N9K-C9804

Nexus 9804

N9K-C9808

Nexus 9808

Not Affected:

  • Other Nexus 9000 models
  • Nexus 9000 fabric switches in ACI mode
  • Nexus 3000 and 7000 lines

Affected NX-OS Releases:

Cisco lists 45 NX-OS releases, from 10.3(1) through 10.6(3s), as affected.

How to Fix It

Cisco didn't publish a simple fixed-release table. Instead, you need to use their Software Checker to find the right version for your device.

Your Options:

1. Upgrade to the Fixed Release

Go to Cisco's Software Checker. Find the correct release for your model. The shield's release notes state that its operational mode transitions to N/A on upgrade to NX-OS 10.6(4) or higher.

2. Use iACL (Infrastructure Access Control List)

Block TCP packets to a locally configured IP address on destination port 43210 or 43211. This has been proven in a test environment.

3. Apply the Live Protect Shield

Temporary mitigation available for:

  • NX-OS 10.6(3)
  • NX-OS 10.6(3s) for the two Smart Switches

Not Supported:

The Live Protect shield doesn't work on the Nexus 9804 and 9808. It also needs SSH, Telnet, or NX-API access.

The Live Protect Shield: What You Need to Know

The Live Protect shield (lp00031) is a temporary fix for customers who can't upgrade right away. 

Here's what you should know:

  • It only works on NX-OS 10.6(3) and, with a second package, on 10.6(3s) for the two Smart Switches
  • It doesn't work on the Nexus 9804 and 9808
  • You need SSH, Telnet, or NX-API access to use it
  • Once you upgrade to NX-OS 10.6(4) or higher, the shield turns off automatically

IOS XR Hardening Release

Cisco also released an IOS XR hardening update bundling 7 umbrella CVEs.

The 9.8 CVEs:

  • CVE-2026-20274: Memory-safety and resource-lifetime bugs
  • CVE-2026-20279: Access-control bugs (missing authentication, improper certificate validation)

The Others:

CVE-2026-20275 through 20278 and CVE-2026-20280 top out between 8.2 and 8.8.

Who's Affected:

The vulnerabilities affect all releases regardless of device configuration.

The SMU Approach:

Software Maintenance Updates are available for specific releases.

Release

Status

6.9.2, 7.3.2, 7.9.2, 7.9.21

SMU available

7.10.2, 7.11.2, 7.11.21

SMU available

24.2.2, 24.2.21, 24.4.2

SMU available

25.2.21, 25.4.1, 25.4.2

SMU available

26.1.2, 26.2.1

SMU available

24.1.2, 24.3.2, 25.1.2, 25.2.2

Future releases


The Numbers:

The Hacker News cross-checked the seven CVE records against the advisory. Of the 111 IOS XR releases Cisco lists as affected:

  • 14 have SMUs available today
  • 4 are awaiting SMUs
  • 93 must first be upgraded before a fix can be applied
  • That's a lot of work for network administrators.

SMU Function Areas

Here's what each SMU covers:

Area

SMU

All XR7 (LNT) platforms

CSCwv19790

BGP

CSCwu14807

crypto-ike

CSCwv19170

gRPC

CSCwt41683

IP-SLA

CSCwv19173

IS-IS

CSCwv45645, CSCwv19171

MPLS and MPLS-TE

CSCwv40753, CSCwu14825

Multicast

CSCwv19180, CSCwu08799

OSPF

CSCwv40741, CSCwv19171

Segment routing (IPv6)

CSCwu13268, CSCwv56312

Segment routing (IPv4)

CSCwv38342

TCP Authentication Option

CSCwv36143

Zero Touch Provisioning

CSCwu36622

The Fire Ant Connection

The Cisco Nexus CVE-2026-20212 vulnerability comes six days after Sygnia reported on Fire Ant, a China-nexus threat actor.

What Fire Ant Does:

Runs purpose-built implants on IOS XR routers

Suppresses syslog delivery (so you don't see logs)

Filters show command output (so you don't see what's happening)

Supports hidden GRE tunnels

What Sygnia Found:

The actor captured packets from routers, uploaded them to external FTP servers, and made connection attempts and port scans against connected systems associated with critical infrastructure.

The Investigation:

Sygnia began with a tunnel interface active on a router with no running configuration or commit history to explain it. This suggested the device's operational state "could no longer be trusted to match the configuration and audit records."

What's Unknown:

Sygnia did not identify how the actor first gained access to the routers or name any vulnerability.

Fire Ant’s Techniques: More Insights

Through the investigation by Sygnia, some techniques used by Fire Ant included:

1. Log Suppression

Suppression of syslog submission prevented security analysts from viewing vital information.

2. Command Filtering

Filtering of command outputs was done to ensure that its existence was not revealed.

3. Hidden Tunnels

Hidden Generic Routing Encapsulation tunnels were used to facilitate secret communication by the attacker.

4. Packet Capture

Packet captures from the routers were sent to FTP servers outside the network.

5. Lateral Movement

Connection attempts and port scans were done on connected systems relating to critical infrastructure.

What Administrators Should Do

For Nexus 9000 Users:

  • Check if you have any affected models
  • Use Cisco's Software Checker to find the fixed release
  • Upgrade immediately
  • If you can't upgrade, apply iACL blocking ports 43210 and 43211

For IOS XR Users:

  • Check if your release has an SMU available
  • Apply the SMU or upgrade to a fixed release
  • Contact TAC if you're running a release outside the table

General:

  • Monitor for suspicious activity
  • Review device configurations for unauthorized changes
  • Watch for unexplained tunnel interfaces
  • Check for suppressed syslog messages
  • Verify show command output for anomalies

The Bottom Line

Cisco patched a critical RCE vulnerability in 10 Nexus 9000 switches. The flaw allows root access via ports 43210 and 43211. IOS XR hardening release also available. Fire Ant is actively targeting IOS XR routers with sophisticated implants.

What You Need to Know:

Key Point

Detail

Vulnerability

CVE-2026-20212

CVSS Score

9.8

Affected

10 Nexus 9000 models

Impact

Root RCE

Patch

Available via Software Checker

Fire Ant

China-nexus actor targeting routers

What You Need to Do:

  • Check affected models
  • Use Cisco's Software Checker
  • Upgrade or apply workarounds
  • Monitor for suspicious activity

FAQ Section

What is CVE-2026-20212?

A critical vulnerability in 10 Cisco Nexus 9000 switches. It allows unauthenticated remote attackers to execute code as root via TCP ports 43210 and 43211.

Which models are affected?

N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808.

What is the IOS XR hardening release?

A release bundling 7 umbrella CVEs. Two are rated 9.8. SMUs are available for many releases.

What is Fire Ant?

A China-nexus threat actor running purpose-built implants on IOS XR routers. They suppress logs, filter commands, and use hidden GRE tunnels.

What should I do?

Use Cisco's Software Checker to find the fixed release. Upgrade or apply iACL and Live Protect shield. Monitor for suspicious activity.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067