
CVE-2026-20212 Binds Nexus 9000 TCP Ports 43210/43211 to Default VRF Enabling Root RCE
CVE-2026-20212 exposes root RCE on ten Nexus 9000 models through default VRF binding on two TCP ports. No public exploits are confirmed yet, but the disclosure model and mitigation constraints increase near-term risk. Operators must cross-check procurement data against the affected PID list and apply iACLs or shields immediately.
The flaw stems from an S1HAL service listening on all interfaces rather than management VRF only. Attackers reaching the switch IP on either port can supply crafted payloads that execute with root privileges; the same path can also trigger process crashes and reloads. Affected PIDs include N9324C-SE1U through N9K-C9808; ACI-mode fabrics, 3000, and 7000 series remain out of scope. Cisco published no fixed-release table and instead routes customers through its Software Checker while listing 45 NX-OS releases from 10.3(1) to 10.6(3s) as vulnerable.
Procurement records and prior Cisco advisories show repeated exposure of control-plane services on data-plane VRFs in Nexus platforms since 2022. The absence of a public fixed-release matrix mirrors the pattern seen in CVE-2023-20198 where customers had to query internal tools. Temporary mitigations—an iACL denying the two ports and Live Protect shield lp00031—are limited to NX-OS 10.6(3) and require SSH or NX-API access, creating an operational gap for air-gapped or minimally managed fabrics.
The simultaneous IOS XR hardening release bundles seven CVEs under umbrella scoring, two rated 9.8, affecting every XR version with no configuration workaround. This dual disclosure under the twice-monthly model reduces the window between publication and potential exploitation. Operators running mixed NX-OS and XR estates now face coordinated upgrade campaigns across distinct code bases.
Next steps hinge on whether independent researchers publish PoCs within 14 days; historical telemetry from Shodan and Censys indicates several thousand exposed Nexus 9000 devices reachable on public prefixes. Organizations should validate iACL coverage in test environments before production rollout and monitor Cisco’s Software Checker for the first fixed 10.6(4) images.
Cisco: At least one public PoC targeting ports 43210/43211 will appear on GitHub within 21 days of disclosure.
Sources (3)
- [1]Cisco Security Advisory(https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nexus-root-execution)
- [2]The Hacker News Report(https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html)
- [3]CVE Program Record(https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20212)