Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cybersecurity · September 4, 2026

Cybersecurity·thehackernews.com

Cisco has shipped patches for a critical vulnerability, tracked as CVE-2026-20212 and rated 9.8 on the CVSS scale, affecting ten Silicon One-based Nexus 9000 switch models. The flaw lets an unauthenticated attacker execute code as root over the network, and Cisco paired the fix with a broader IOS XR hardening release covering seven additional CVEs, two of them also critical, with no workaround available. Network operators running affected Nexus 9000 hardware should prioritize patching immediately.

// source: thehackernews.com ↗

Back to Blog