CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5646

As cited

Copy frozen at (site build).

vulnerabilities

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco released patches for CVE-2026-20212, a critical flaw in 10 Silicon One-based Nexus 9000 switches that carries a CVSS score of 9.8 and allows unauthenticated, remote attackers to execute code as root. The vendor also issued an IOS XR hardening release addressing seven umbrella CVEs, including two rated 9.8, with no available workaround for any IOS XR version.

Why it matters: Organizations running affected Nexus 9000 switches or IOS XR need to patch immediately, as unauthenticated remote code execution as root requires no user interaction and exposes the network to complete control compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco released patches for CVE-2026-20212, a critical flaw in 10 Silicon One-based Nexus 9000 switches that carries a CVSS score of 9.8 and allows unauthenticated, remote attackers to execute code as root. The vendor also issued an IOS XR hardening release addressing seven umbrella CVEs, including two rated 9.8, with no available workaround for any IOS XR version.

Why it matters: Organizations running affected Nexus 9000 switches or IOS XR need to patch immediately, as unauthenticated remote code execution as root requires no user interaction and exposes the network to complete control compromise.

VendorsAppleCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary