T
Threats
Cisco NX-OS and IOS XR Critical Vulnerabilities
Overview
Severity: Critical
Highest CVSS: 9.8
Date: 4 September 2026
Cisco has released updates for critical vulnerabilities in Cisco NX-OS Software on selected Nexus 9000 Series Switches and in Cisco IOS XR Software. The most direct risk is CVE-2026-20212, which can allow an unauthenticated remote attacker to execute code with root privileges or crash the S1HAL process, potentially causing a device reload.
The IOS XR issues were identified through Cisco's internal security review and are not known to be actively exploited. Cisco has grouped the underlying flaws by vulnerability class, so each IOS XR CVE represents multiple issues within a CWE category rather than a single technical flaw.
Affected Versions
Cisco NX-OS Software - CVE-2026-20212
Affected: Cisco Nexus 9000 Series Switches containing a Silicon One ASIC with the following product identifiers: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804 and N9K-C9808. The vendor has not specified an exact affected-version range as of 2 September 2026.
Fixed: Cisco has released fixed software, but the advisory does not enumerate fixed release numbers. Use the Cisco Software Checker to identify the first fixed release for the deployed platform and release.
Not affected: Nexus 9000 Series models not listed above and Nexus 9000 Series Fabric Switches in ACI mode are not affected. Cisco also confirms that Nexus 3000 and 7000 Series Switches, MDS 9000 Series Switches, listed Firepower and Secure Firewall platforms, listed UCS Fabric Interconnects, and UCS X-Series Direct Fabric Interconnect 9108 100G are not affected.
Source: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
Cisco IOS XR Software - CVE-2026-20274 and CVE-2026-20279
Affected: All releases of Cisco IOS XR Software, including IOS XR7 (LNT), regardless of device configuration.
Fixed: SMUs are available for 7.3.2; 7.9.2 and 7.9.21; 7.10.2; 7.11.2 and 7.11.21; 24.2.2 and 24.2.21; 24.4.2; 25.2.21; 25.4.1 and 25.4.2; 26.1.2; and 26.2.1. SMUs are planned for 24.1.2, 24.3.2, 25.1.2 and 25.2.2. Cisco identifies 26.2.2 and 26.3.1 as future first fixed releases that will not require SMUs. Applicability varies by platform and functional area.
Not affected: Cisco documents limited exceptions by functional area, release and platform. Examples include BGP on 7.10 and earlier trains and 26.2.1; IS-IS and IPv6 segment routing on 26.1.2 and 26.2.1; and ZTP on 26.2.1. Confirm the applicable SMUs and exceptions in the advisory before deployment.
Source: Cisco IOS XR Software Security Hardening Release: September 2026
Vulnerability Breakdown
CVE-2026-20212 - Silicon One Remote Code Execution
Severity: Critical
CVSS: 9.8
Description: TCP ports 43210 and 43211 are accessible in the default Layer 3 VRF on affected Nexus 9000 Series Switches. An unauthenticated remote attacker can connect to an affected device and submit crafted input.
Impact: Successful exploitation may execute code with root privileges. Exploitation may also crash the S1HAL process and cause the device to reload.
Conditions: Network access to TCP port 43210 or 43211 on a locally configured device IP address. No authentication or user interaction is required.
CVE-2026-20274 - Improper Resource Control
Severity: Critical
CVSS: 9.8 maximum for the grouped category
Description: This CVE groups internally discovered Cisco IOS XR flaws under CWE-664, improper control of a resource through its lifetime. The category includes memory-safety, resource-allocation and insecure-initialisation weaknesses.
Impact: The highest-rated underlying issue can affect confidentiality, integrity and availability. Cisco does not publish a separate impact statement for every underlying flaw in the grouped advisory.
Conditions: Cisco does not publish per-flaw exploit prerequisites. The maximum CVSS vector for the advisory is network-based, low complexity, with no privileges or user interaction required.
CVE-2026-20279 - Improper Access Control
Severity: Critical
CVSS: 9.8 maximum for the grouped category
Description: This CVE groups internally discovered Cisco IOS XR flaws under CWE-284, improper access control. The category covers certificate-validation, authentication and authorisation weaknesses.
Impact: The highest-rated underlying issue can affect confidentiality, integrity and availability. Cisco does not publish a separate impact statement for every underlying flaw in the grouped advisory.
Conditions: Cisco does not publish per-flaw exploit prerequisites. The maximum CVSS vector for the advisory is network-based, low complexity, with no privileges or user interaction required.
Mitigation
Upgrade affected Cisco Nexus 9000 Series Switches to a fixed NX-OS release identified through the Cisco Software Checker.
Until upgrades are complete, use infrastructure access control lists to allow only required management and control-plane traffic to affected devices, or explicitly deny TCP traffic to locally configured IP addresses on ports 43210 and 43211.
Consider Cisco's Live Protect shield for CVE-2026-20212 as a temporary mitigation. Cisco states that upgrading remains necessary for full remediation.
For Cisco IOS XR, move to a release with available SMUs and apply the SMUs appropriate to each platform and functional area.
Where no listed IOS XR release or SMU meets operational requirements, open a Cisco TAC service request or contact the organisation's Cisco support provider.
Summary for IT Teams
Products: Cisco NX-OS Software on selected Nexus 9000 Series Switches; Cisco IOS XR Software
Threat Level: Critical, CVSS 9.8
Action Required: Identify affected Nexus 9000 models and IOS XR systems, restrict access to NX-OS ports 43210 and 43211 where applicable, then deploy Cisco's fixed releases and relevant IOS XR SMUs as a priority.
Reference
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
Cisco IOS XR Software Security Hardening Release: September 2026
Cisco NX-OS Software Hardening Guide
Need Help?
Secure ISS can help assess exposure, prioritise remediation and coordinate patching across affected Cisco environments. Contact the Secure ISS team on 1300 769 460.

