Patch released Cisco Nexus 9000 rce Cisco IOS XR Cisco network-edge
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
CVE Tools coverage
Cisco has issued updates for a critical vulnerability, identified as CVE-2026-20212 with a CVSS score of 9.8, affecting ten models of Silicon One-based Nexus 9000 switches. This defect allows unauthenticated remote attackers to achieve root-level code execution by sending crafted input to exposed TCP ports 43210 and 43211 within the default Layer 3 VRF instance. Alongside this specific fix, Cisco released an IOS XR hardening update addressing seven umbrella CVEs, two of which carry a maximum severity rating of 9.8, impacting all versions without available workarounds.