Cisco disclosed a critical, unauthenticated remote-code-execution flaw in Nexus 9000 Series switches built on Silicon One ASICs on September 2, tracked as CVE-2026-20212 with a CVSS score of 9.8. The bug lives in ports 43210 and 43211, which are reachable in the default Layer 3 VRF, and lets an attacker “connect to an affected device and send crafted input that could be executed as code with root privileges,” according to Cisco’s advisory. Cisco said it found the flaw while resolving a Technical Assistance Center support case, and that it is “not aware of any public announcements or malicious use of the vulnerability.”

The severity here is not abstract. Root code execution on the switching fabric underneath a data center, reachable without any credentials, is one of the small number of bug classes that can turn a single unpatched device into a foothold for the whole network segment behind it, particularly in the AI-heavy data center deployments Silicon One ASICs are built for. Ten specific Nexus 9000 models are affected; Cisco confirmed the ACI-mode fabric switches, Nexus 3000 and 7000 lines, and several other switch and firewall product families are not.

The original insight for security leaders managing this patch cycle: the two named ports are unusual enough, and specific enough, that an infrastructure access control list restricting 43210 and 43211 to known management traffic is a genuinely effective stopgap, not just a compliance checkbox, while the fixed NX-OS release rolls out. Cisco is also offering a temporary “Live Protect” shield ahead of a full upgrade. Given how CyberTech has covered a run of vulnerabilities converting ordinary access into root access this year, treat any unauthenticated root-RCE advisory on core infrastructure as a same-week priority, not a routine patch-window item, and confirm the ACL is in place before assuming the vendor timeline covers you, a lesson also visible in how fast a similarly rated flaw moved from disclosure to active exploitation this year.

Source: Cisco