Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Summary

Cisco has released patches for a critical vulnerability (CVE-2026-20212) in its Nexus 9000 switches that allows unauthenticated remote attackers to execute code as root. The vulnerability has a CVSS score of 9.8 and no workaround exists for any IOS XR version. Cisco also released an IOS XR hardening release with seven umbrella CVEs, two of which are rated 9.8.

IFF Assessment

FOE

This vulnerability allows unauthenticated remote attackers to gain root access to critical network devices, posing a significant threat to network security.

Severity

9.8 Critical

Defender Context

Network defenders should prioritize patching Cisco Nexus 9000 switches immediately due to the critical nature of CVE-2026-20212, which allows for unauthenticated remote root code execution. The lack of a workaround for any IOS XR version underscores the urgency, as attackers could exploit this to gain full control of network infrastructure.

Read Full Story →