Cisco Patches Critical RCE Flaw in Nexus Switches, Addresses Broad IOS XR Vulnerabilities
Cisco has released urgent patches for a critical remote code execution (RCE) vulnerability affecting ten **Silicon One-based Nexus 9000 switches**, allowing unauthenticated attackers to gain root access. Concurrently, a comprehensive **IOS XR** hardening release bundles seven new CVEs, two of which are rated 9.8, impacting all versions with no immediate workarounds.

**Cisco** has issued critical security updates to address a severe remote code execution (RCE) vulnerability impacting a subset of its **Nexus 9000** series switches. Tracked as **CVE-2026-20212** (CVSS score: 9.8), this flaw could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges.
### Nexus 9000 RCE Vulnerability
The **CVE-2026-20212** vulnerability stems from an unrestricted IP address binding that leaves TCP ports 43210 and 43211 exposed in the default Layer 3 virtual routing and forwarding (VRF) instance. An attacker with network access to the switch on either of these ports can connect to the service and send crafted input, leading to code execution as root.
Successful exploitation could also crash the **S1HAL** process, causing the device to reload. As of its September 2 disclosure, Cisco stated it was unaware of any active malicious exploitation of this flaw.
Cisco has not published a fixed-release table for this issue, instead directing customers to its **Software Checker** tool. Interim mitigations include implementing an infrastructure access control list (iACL) to block the two vulnerable ports and deploying a temporary **Live Protect** shield.
Affected **Nexus 9000** product identifiers (PIDs) include:
* N9324C-SE1U (Nexus Smart Switch)
* N9348Y2C6D-SE1U (Nexus Smart Switch)
* N9364E-SG2-O
* N9364E-SG2-Q
* N9396T12C-SE1
* N9348Y12C-SE1
* N9396Y12C-SE1
* N9336C-SE1
* N9K-C9804
* N9K-C9808
Other Nexus 9000 models, those running in Application Centric Infrastructure (ACI) mode, and the Nexus 3000 and 7000 lines are not affected. The **CVE Program's** record confirms that **NX-OS** releases from 10.3(1) through 10.6(3s) are impacted.
Recommended actions until a confirmed fixed release is available include:
* **Upgrade** to the release specified by **Cisco's Software Checker**.
* Implement an **iACL** to either permit only essential management/control-plane traffic or explicitly deny TCP packets to destination ports 43210 and 43211.
* Deploy **Live Protect shield lp00031**, a temporary mitigation for specific **NX-OS** versions.
### Broad IOS XR Hardening Release
In parallel, Cisco has rolled out a significant hardening release for **IOS XR**, addressing a bundle of seven vulnerabilities. This release follows **Cisco's** new twice-monthly disclosure model, grouping internally found bugs into umbrella CVEs.
Two of these vulnerabilities, **CVE-2026-20274** (covering memory-safety and resource-lifetime bugs) and **CVE-2026-20279** (addressing access-control issues like missing authentication and improper certificate validation), carry a critical CVSS score of 9.8.
The remaining five CVEs (**CVE-2026-20275** through **20278** and **CVE-2026-20280**) are rated between 8.2 and 8.8. These vulnerabilities affect all **IOS XR** releases regardless of device configuration.
For **IOS XR7 (LNT)** platforms, including the **Cisco 8000 Series**, **NCS 1010**, **NCS 540L**, and **NCS 5700 Series**, a dedicated Software Maintenance Update (SMU) is available across all releases.
Cisco advises customers to upgrade to a release that includes SMUs and then apply them. Future releases 26.2.2 and 26.3.1 are expected to be the first fixed releases that will not require SMUs. Customers running releases outside the provided table should open a Technical Assistance Center (TAC) case.
SMUs are currently available for numerous **IOS XR** releases, including:
* 6.9.2
* 7.3.2
* 7.9.2
* 7.9.21
* 7.10.2
* 7.11.2
* 7.11.21
* 24.2.2
* 24.2.21
* 24.4.2
* 25.2.21
* 25.4.1
* 25.4.2
* 26.1.2
* 26.2.1
SMUs are also listed as future releases for 24.1.2, 24.3.2, 25.1.2, and 25.2.2. The advisory details specific SMU identifiers by functional area, covering components like BGP, crypto-ike, gRPC, IP-SLA, IS-IS, MPLS, Multicast, OSPF, Segment routing (IPv6 and IPv4), TCP Authentication Option, and Zero Touch Provisioning (ZTP).
This marks the third scheduled hardening release in 30 days, following previous updates for **IOS XE**, **Catalyst SD-WAN**, **Crosswork**, and **Secure Workload**.
Separately, two publicly disclosed **Secure/Multipurpose Internet Mail Extensions (S/MIME)** decryption flaws in **Secure Email**, **CVE-2026-20354** and **CVE-2026-20355** (CVSS scores: 5.9), allow a machine-in-the-middle attacker to recover plaintext from encrypted emails.