On 2 September 2026, Cisco released patches for critical vulnerability CVE-2026-20212 (CVSS 9.8) in ten Silicon One–based Nexus 9000 switch models, which allows an unauthenticated remote attacker to execute arbitrary code with root privileges. At the same time, a IOS XR hardening release was published, consolidating seven umbrella CVEs — two of which are also rated 9.8 — and affecting all IOS XR versions without exception and with no workarounds. Organizations operating affected equipment must immediately assess the applicability of patches and temporary protections.
CVE-2026-20212: remote code execution in Nexus 9000
The vulnerability is related to a service being bound to an unrestricted IP address, which makes TCP ports 43210 and 43211 reachable in the default L3 VRF instance. An attacker who can reach the switch’s IP address on either of these ports can connect directly to the service. Specially crafted data sent to this service is executed as code with root privileges. In addition, an exploitation attempt may cause the S1HAL process to crash and the device to reboot, according to Cisco’s official advisory.
The following product identifiers are affected (check with the show module command):
- N9324C-SE1U and N9348Y2C6D-SE1U (Nexus Smart Switch)
- N9364E-SG2-O and N9364E-SG2-Q
- N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1
- N9336C-SE1
- N9K-C9804 and N9K-C9808
Other Nexus 9000 models, Nexus 9000 switches in ACI mode, as well as the Nexus 3000 and Nexus 7000 families are not affected. Cisco states that at the time of publication it is not aware of malicious exploitation of the vulnerability — however, this is only the vendor’s statement and does not rule out the possibility of attacks that have not been observed.
Temporary mitigations for Nexus
Cisco has not published a fixed release matrix and directs customers to the interactive Software Checker to determine the target NX-OS version. Until upgrading, two temporary mechanisms are offered:
- iACL — an infrastructure access control list that allows only necessary management traffic, or explicitly blocks TCP packets to ports 43210 and 43211 for locally configured IP addresses. Cisco emphasizes that rules must be tested in a lab environment before deployment.
- Live Protect shield lp00031 — a temporary protection mechanism supported on NX-OS 10.6(3) and, via a separate package, on NX-OS 10.6(3s) for two Smart Switch models. The mechanism is not supported on N9K-C9804 and N9K-C9808 and requires access via SSH, Telnet, or NX-API. According to the release notes, after upgrading to NX-OS 10.6(4) or later, the shield operating mode transitions to N/A status.
IOS XR hardening: seven umbrella CVEs
In parallel, Cisco published an IOS XR hardening advisory covering seven CVEs, grouped by CWE categories under a risk-based disclosure model. Each umbrella CVE is assigned the CVSS score of the most severe defect in the group:
- CVE-2026-20274 (CVSS 9.8) — memory safety and resource lifetime management errors
- CVE-2026-20279 (CVSS 9.8) — access control flaws, including missing authentication for critical functions and incorrect certificate validation
- CVE-2026-20275 (CVSS 8.8), CVE-2026-20278 (CVSS 8.8), CVE-2026-20280 (CVSS 8.8)
- CVE-2026-20276 (CVSS 8.6)
- CVE-2026-20277 (CVSS 8.2)
Crucially, the vulnerabilities affect all IOS XR versions regardless of device configuration, including XR7 (LNT) platforms — Cisco 8000 Series, NCS 1010, NCS 540L, and NCS 5700 Series. No workarounds exist.
IOS XR remediation process
Cisco requires customers to upgrade to a version for which SMUs (Software Maintenance Updates) are available and then apply the relevant updates. SMUs are available for 15 versions — from 6.9.2 to 26.2.1. For four versions (24.1.2, 24.3.2, 25.1.2, 25.2.2), SMUs are planned for future release. The first fully fixed releases that do not require SMUs will be versions 26.2.2 and 26.3.1.
For XR7 (LNT) platforms, a single SMU, CSCwv19790, applies across all versions. The remaining SMUs are tied to functional areas: BGP, crypto-ike, gRPC, IP-SLA, IS-IS, MPLS/MPLS-TE, multicast, OSPF, segment routing, TCP Authentication Option, and ZTP. The applicability of individual SMUs varies by version, platform, and CPU architecture. Customers running versions that do not appear in the advisory’s matrix are advised to open a TAC case.
Additional advisories from 2 September
On the same day, Cisco published two more advisories:
- CVE-2026-20354 and CVE-2026-20355 (CVSS 5.9) — S/MIME decryption vulnerabilities in Cisco Secure Email, allowing an attacker in a man-in-the-middle position to recover plaintext from email between gateways running AsyncOS 16.5.0 and earlier with S/MIME configured.
- CVE-2026-20281 (CVSS 7.5) — denial of service in Cisco IP phones (Desk Phone 9800, IP Phone 7800/8800, Video Phone 8875) when registered to Unified CM with Web Access enabled (disabled by default).
Impact assessment
The September release is the third scheduled hardening bundle in 30 days, reflecting Cisco’s move to a twice-monthly disclosure model. The scope of affected products is significant: CVE-2026-20212 impacts switches used in data center cores, while the IOS XR vulnerabilities affect routers that form the backbone of service provider and large enterprise networks.
The CVSS 9.8 ratings for the IOS XR umbrella CVEs should be interpreted with a caveat: they represent the most severe defect within each CWE group, not every individual issue. Nonetheless, the absence of workarounds and the coverage of all IOS XR versions make upgrading the only viable option.
Recommendations
- Nexus 9000: immediately verify the product identifier with the
show modulecommand. If it matches an affected PID, apply an iACL to block TCP ports 43210 and 43211, determine the target NX-OS version via the Software Checker, and schedule an upgrade. For NX-OS 10.6(3), consider deploying the Live Protect shield lp00031. - IOS XR: determine your current version and platform, compare them against the SMU matrix in the advisory, upgrade to a version with available SMUs, and apply all applicable updates. If your version is not listed in the matrix, open a TAC case.
- Secure Email: check the AsyncOS version and S/MIME configuration between gateways; if a vulnerable configuration is present, refer to the defect records for information on fixed releases.
- IP phones: if Web Access is enabled on affected models, upgrade SIP Software to the version specified in the advisory or disable Web Access until the upgrade is completed.
Given the criticality of CVE-2026-20212 and the lack of workarounds for IOS XR, patching priority for both product lines should be maximal. For Nexus 9804 and 9808 switches, where Live Protect shield is not supported, iACL remains the only effective measure before upgrading — its deployment should be treated as a top-priority action in the hours immediately following the advisory’s publication.