Cisco Nexus
Cisco just dropped patches for a critical security flaw affecting 10 of its Nexus 9000 switches. The vulnerability, tracked as CVE-2026-20212, allows attackers to execute code as root on affected devices. No authentication required. No credentials needed.
At the same time, Cisco released an IOS XR hardening update that bundles seven umbrella CVEs. Two of them are rated 9.8 on the CVSS scale.
Let me break down what's happening and what you need to do.
Quick Summary
|
What |
Details |
|
Vulnerability |
CVE-2026-20212 |
|
CVSS Score |
9.8 (Critical) |
|
Affected |
10 Nexus 9000 switches |
|
Impact |
Root RCE, device reload |
|
Patch |
Available via Software Checker |
|
Workarounds |
iACL, Live Protect shield |
The Nexus Vulnerability
What's the Problem?
The flaw leaves TCP ports 43210 and 43211 exposed in the default Layer 3 VRF instance. An attacker who can reach a switch's address on either port can connect directly. Once connected, they send crafted input that gets executed as code with root privileges.
The Impact:
- Remote code execution as root
- Device crash and reload
- Full compromise of the switch
The Good News:
Cisco said it's not aware of any malicious use of the flaw as of its September 2 disclosure. But that doesn't mean you should wait.
Affected Nexus 9000 Models
Here are the 10 models that are vulnerable:
|
PID |
Model |
|
N9324C-SE1U |
Nexus Smart Switch |
|
N9348Y2C6D-SE1U |
Nexus Smart Switch |
|
N9364E-SG2-O |
— |
|
N9364E-SG2-Q |
— |
|
N9396T12C-SE1 |
— |
|
N9348Y12C-SE1 |
— |
|
N9396Y12C-SE1 |
— |
|
N9336C-SE1 |
— |
|
N9K-C9804 |
Nexus 9804 |
|
N9K-C9808 |
Nexus 9808 |
Not Affected:
- Other Nexus 9000 models
- Nexus 9000 fabric switches in ACI mode
- Nexus 3000 and 7000 lines
Affected NX-OS Releases:
Cisco lists 45 NX-OS releases, from 10.3(1) through 10.6(3s), as affected.
How to Fix It
Cisco didn't publish a simple fixed-release table. Instead, you need to use their Software Checker to find the right version for your device.
Your Options:
1. Upgrade to the Fixed Release
Go to Cisco's Software Checker. Find the correct release for your model. The shield's release notes state that its operational mode transitions to N/A on upgrade to NX-OS 10.6(4) or higher.
2. Use iACL (Infrastructure Access Control List)
Block TCP packets to a locally configured IP address on destination port 43210 or 43211. This has been proven in a test environment.
3. Apply the Live Protect Shield
Temporary mitigation available for:
- NX-OS 10.6(3)
- NX-OS 10.6(3s) for the two Smart Switches
Not Supported:
The Live Protect shield doesn't work on the Nexus 9804 and 9808. It also needs SSH, Telnet, or NX-API access.
The Live Protect Shield: What You Need to Know
The Live Protect shield (lp00031) is a temporary fix for customers who can't upgrade right away.
Here's what you should know:
- It only works on NX-OS 10.6(3) and, with a second package, on 10.6(3s) for the two Smart Switches
- It doesn't work on the Nexus 9804 and 9808
- You need SSH, Telnet, or NX-API access to use it
- Once you upgrade to NX-OS 10.6(4) or higher, the shield turns off automatically
IOS XR Hardening Release
Cisco also released an IOS XR hardening update bundling 7 umbrella CVEs.
The 9.8 CVEs:
- CVE-2026-20274: Memory-safety and resource-lifetime bugs
- CVE-2026-20279: Access-control bugs (missing authentication, improper certificate validation)
The Others:
CVE-2026-20275 through 20278 and CVE-2026-20280 top out between 8.2 and 8.8.
Who's Affected:
The vulnerabilities affect all releases regardless of device configuration.
The SMU Approach:
Software Maintenance Updates are available for specific releases.
|
Release |
Status |
|
6.9.2, 7.3.2, 7.9.2, 7.9.21 |
SMU available |
|
7.10.2, 7.11.2, 7.11.21 |
SMU available |
|
24.2.2, 24.2.21, 24.4.2 |
SMU available |
|
25.2.21, 25.4.1, 25.4.2 |
SMU available |
|
26.1.2, 26.2.1 |
SMU available |
|
24.1.2, 24.3.2, 25.1.2, 25.2.2 |
Future releases |
The Numbers:
The Hacker News cross-checked the seven CVE records against the advisory. Of the 111 IOS XR releases Cisco lists as affected:
- 14 have SMUs available today
- 4 are awaiting SMUs
- 93 must first be upgraded before a fix can be applied
- That's a lot of work for network administrators.
SMU Function Areas
Here's what each SMU covers:
|
Area |
SMU |
|
All XR7 (LNT) platforms |
CSCwv19790 |
|
BGP |
CSCwu14807 |
|
crypto-ike |
CSCwv19170 |
|
gRPC |
CSCwt41683 |
|
IP-SLA |
CSCwv19173 |
|
IS-IS |
CSCwv45645, CSCwv19171 |
|
MPLS and MPLS-TE |
CSCwv40753, CSCwu14825 |
|
Multicast |
CSCwv19180, CSCwu08799 |
|
OSPF |
CSCwv40741, CSCwv19171 |
|
Segment routing (IPv6) |
CSCwu13268, CSCwv56312 |
|
Segment routing (IPv4) |
CSCwv38342 |
|
TCP Authentication Option |
CSCwv36143 |
|
Zero Touch Provisioning |
CSCwu36622 |
The Fire Ant Connection
The Cisco Nexus CVE-2026-20212 vulnerability comes six days after Sygnia reported on Fire Ant, a China-nexus threat actor.
What Fire Ant Does:
Runs purpose-built implants on IOS XR routers
Suppresses syslog delivery (so you don't see logs)
Filters show command output (so you don't see what's happening)
Supports hidden GRE tunnels
What Sygnia Found:
The actor captured packets from routers, uploaded them to external FTP servers, and made connection attempts and port scans against connected systems associated with critical infrastructure.
The Investigation:
Sygnia began with a tunnel interface active on a router with no running configuration or commit history to explain it. This suggested the device's operational state "could no longer be trusted to match the configuration and audit records."
What's Unknown:
Sygnia did not identify how the actor first gained access to the routers or name any vulnerability.
Fire Ant’s Techniques: More Insights
Through the investigation by Sygnia, some techniques used by Fire Ant included:
1. Log Suppression
Suppression of syslog submission prevented security analysts from viewing vital information.
2. Command Filtering
Filtering of command outputs was done to ensure that its existence was not revealed.
3. Hidden Tunnels
Hidden Generic Routing Encapsulation tunnels were used to facilitate secret communication by the attacker.
4. Packet Capture
Packet captures from the routers were sent to FTP servers outside the network.
5. Lateral Movement
Connection attempts and port scans were done on connected systems relating to critical infrastructure.
What Administrators Should Do
For Nexus 9000 Users:
- Check if you have any affected models
- Use Cisco's Software Checker to find the fixed release
- Upgrade immediately
- If you can't upgrade, apply iACL blocking ports 43210 and 43211
For IOS XR Users:
- Check if your release has an SMU available
- Apply the SMU or upgrade to a fixed release
- Contact TAC if you're running a release outside the table
General:
- Monitor for suspicious activity
- Review device configurations for unauthorized changes
- Watch for unexplained tunnel interfaces
- Check for suppressed syslog messages
- Verify show command output for anomalies
The Bottom Line
Cisco patched a critical RCE vulnerability in 10 Nexus 9000 switches. The flaw allows root access via ports 43210 and 43211. IOS XR hardening release also available. Fire Ant is actively targeting IOS XR routers with sophisticated implants.
What You Need to Know:
|
Key Point |
Detail |
|
Vulnerability |
CVE-2026-20212 |
|
CVSS Score |
9.8 |
|
Affected |
10 Nexus 9000 models |
|
Impact |
Root RCE |
|
Patch |
Available via Software Checker |
|
Fire Ant |
China-nexus actor targeting routers |
What You Need to Do:
- Check affected models
- Use Cisco's Software Checker
- Upgrade or apply workarounds
- Monitor for suspicious activity
FAQ Section
What is CVE-2026-20212?
A critical vulnerability in 10 Cisco Nexus 9000 switches. It allows unauthenticated remote attackers to execute code as root via TCP ports 43210 and 43211.
Which models are affected?
N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808.
What is the IOS XR hardening release?
A release bundling 7 umbrella CVEs. Two are rated 9.8. SMUs are available for many releases.
What is Fire Ant?
A China-nexus threat actor running purpose-built implants on IOS XR routers. They suppress logs, filter commands, and use hidden GRE tunnels.
What should I do?
Use Cisco's Software Checker to find the fixed release. Upgrade or apply iACL and Live Protect shield. Monitor for suspicious activity.