Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has released a critical security advisory addressing a remote code execution vulnerability (CVE-2026-20212) in its Nexus 9000 switches. An unauthenticated attacker can execute code as root by binding to an unrestricted IP address, potentially leading to complete system compromise. Cisco recommends immediate upgrades to affected IOS XR releases and implementing temporary mitigations like iACLs and Live Protect shields. The vulnerability has been actively exploited by the Fire Ant threat actor, a Chinese nation-state group, who deployed purpose-built implants to suppress logging and exfiltrate data. The vulnerability affects a wide range of Nexus 9000 models and requires a significant number of updates to remediate.
Cisco has released a critical security advisory addressing a remote code execution vulnerability (CVE-2026-20212) in its Nexus 9000 switches. An unauthenticated attacker can execute code as root by binding to an unrestricted IP address, potentially leading to complete system compromise. The vulnerability is described as binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance. An attacker who can reach a switch's address on either port can connect directly to the service. Crafted input sent to that service is then executed as code with root privileges. An exploitation attempt can also crash the S1HAL process and reload the device.
Cisco said it's not aware of any malicious use of the flaw as of its September 2 disclosure. It has published no fixed-release table and directs customers to its Software Checker, with an infrastructure access control list (iACL) blocking the two ports and a temporary Live Protect shield as stopgaps.
Cisco tells IOS XR customers, including those on IOS XR7 (LNT), to upgrade to a release that includes software maintenance updates (SMUs), then apply them. "At the same time, the window between disclosure and exploitation has effectively closed," Russ Smoak, vice president of information security at Cisco, said in a June blog post announcing the twice-monthly disclosure model that groups internally found bugs into umbrella CVEs.
Cisco lists the following affected product identifiers (PIDs) in its Nexus 9000 advisory, checkable against the output of the show module command -
- N9324C-SE1U (Nexus Smart Switch)
- N9348Y2C6D-SE1U (Nexus Smart Switch)
- N9364E-SG2-O
- N9364E-SG2-Q
- N9396T12C-SE1
- N9348Y12C-SE1
- N9396Y12C-SE1
- N9336C-SE1
- N9K-C9804
- N9K-C9808
Other Nexus 9000 models, Nexus 9000 fabric switches running in Application Centric Infrastructure (ACI) mode, and the Nexus 3000 and 7000 lines are unaffected.
The Hacker News cross-checked the seven CVE records against the advisory on September 3 and found that, of the 111 IOS XR releases Cisco lists as affected, 14 have SMUs available today, four are awaiting SMUs, and 93 must first be upgraded before a fix can be applied.
The September 2 drop is the third scheduled hardening release in 30 days, following the first hardening drop on August 5, which delivered the IOS XE hardening release and a Catalyst SD-WAN release, and two CVSS 10.0 releases for Crosswork and Secure Workload two weeks later.
Separately, the same day's advisories also fixed a phone denial-of-service bug, CVE-2026-20281 (CVSS score: 7.5), in Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 devices registered to Unified Communications Manager with Web Access enabled, a setting that's off by default. Fixes arrive in SIP Software 5.0(1), 14.4(1)SR3, 14.4(1)SR4, or 11.0(6)SR8 depending on the model.
The development comes six days after Sygnia said the China-nexus threat actor Fire Ant, first documented in 2025, ran purpose-built implants on IOS XR routers that suppressed syslog delivery, filtered show command output, and supported a hidden Generic Routing Encapsulation (GRE) tunnel.
The actor also captured packets from routers, uploaded them to external FTP servers, and made connection attempts and port scans against connected systems associated with critical infrastructure.
The investigation began with a tunnel interface active on a router with no running configuration or commit history to explain it, which, Sygnia said in its Fire Ant report, suggested the device's operational state "could no longer be trusted to match the configuration and audit records."
Sygnia did not identify how the actor first gained access to the routers or name any vulnerability. The Hacker News cross-checked the seven CVE records against the advisory on September 3 and found that, of the 111 IOS XR releases Cisco lists as affected, 14 have SMUs available today, four are awaiting SMUs, and 93 must first be upgraded before a fix can be applied.
