CVE-2026-20212 – Cisco NX-OS Software

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“Exposed management ports can turn a network switch into a path for root-level code execution.”

Cisco NX-OS Software contains a critical vulnerability in the Silicon One integration for Nexus 9000 Series Switches. CVE-2026-20212 allows an unauthenticated remote attacker to send crafted input through TCP ports 43210 or 43211 and execute code with root privileges. The CVSS score is 9.8, which is Critical severity.

Successful exploitation can also crash the S1HAL process and force the affected device to reload, creating both system-compromise and availability risk.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-1327
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.