Skip to content
CiscoCVE-2026-20212

Cisco NX-OS Software: remote code execution

Critical9.8CVE-2026-20212 · Published Sep 2, 2026 · updated Sep 3, 2026

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco NX-OS Software
Product
<= 10.3(1)No fix yet
<= 10.3(2)No fix yet
<= 10.3(3)No fix yet
<= 10.4(1)No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Secure Email: insufficient authenticity check
Medium5.9Sep 2
Cisco IOS XR Software: protection mechanism failure
High8.2Sep 2
As part of Cisco's ongoing commitment to proactive security and product quality
High8.8Sep 2
Cisco IOS XR Software: improper access control
Critical9.8Sep 2
Cisco IOS XR Software: unhandled exceptional condition
High8.8Sep 2
Cisco Session Initiation Protocol (SIP) Software: denial of service
High7.5Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.