Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Cybercab is Tesla’s ‘fork in the road’ moment 

    September 3, 2026

    Anthropic Released Claude Commerce Agents: An Apache-2.0 Blueprint for Shopping and Merchant Agents Across Retail, Travel, Telecom and Entertainment

    September 3, 2026

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Cybercab is Tesla’s ‘fork in the road’ moment 
    • Anthropic Released Claude Commerce Agents: An Apache-2.0 Blueprint for Shopping and Merchant Agents Across Retail, Travel, Telecom and Entertainment
    • Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
    • Kraken And SoFi Link Crypto Trading To Banking Rails
    • Curiosity Blog, Sols 4988-4994: More New Tricks for an Old Dog
    • Court Stalls EPA Plan to Override California’s Vehicle Pollution Standards
    • Equinor to deploy cable monitoring tech at 9-year-old offshore wind farm
    • The Guardian view on Nigeria’s kidnappings: a country can’t prosper when going to school is a danger | Editorial
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.

    The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance.

    An attacker who can reach a switch’s address on either port can connect directly to the service. Crafted input sent to that service is then executed as code with root privileges. An exploitation attempt can also crash the S1HAL process and reload the device.

    Cisco said it’s not aware of any malicious use of the flaw as of its September 2 disclosure. It has published no fixed-release table and directs customers to its Software Checker, with an infrastructure access control list (iACL) blocking the two ports and a temporary Live Protect shield as stopgaps.

    Cisco tells IOS XR customers, including those on IOS XR7 (LNT), to upgrade to a release that includes software maintenance updates (SMUs), then apply them.

    “At the same time, the window between disclosure and exploitation has effectively closed,” Russ Smoak, vice president of information security at Cisco, said in a June blog post announcing the twice-monthly disclosure model that groups internally found bugs into umbrella CVEs.

    Cybersecurity

    Cisco lists the following affected product identifiers (PIDs) in its Nexus 9000 advisory, checkable against the output of the show module command –

    • N9324C-SE1U (Nexus Smart Switch)
    • N9348Y2C6D-SE1U (Nexus Smart Switch)
    • N9364E-SG2-O
    • N9364E-SG2-Q
    • N9396T12C-SE1
    • N9348Y12C-SE1
    • N9396Y12C-SE1
    • N9336C-SE1
    • N9K-C9804
    • N9K-C9808

    Other Nexus 9000 models, Nexus 9000 fabric switches running in Application Centric Infrastructure (ACI) mode, and the Nexus 3000 and 7000 lines are unaffected.

    The Hacker News confirmed via the CVE Program’s record on September 3 that Cisco lists 45 NX-OS releases, from 10.3(1) through 10.6(3s), as affected, a range the advisory itself leaves to the Software Checker.

    Until a fixed release is confirmed, Cisco offers the following –

    • Upgrade to the release named by Cisco’s Software Checker; the shield’s release notes state that its operational mode transitions to N/A on upgrade to NX-OS 10.6(4) or higher.
    • iACL permitting only required management and control-plane traffic, or explicitly denying TCP packets to a locally configured IP address on destination port 43210 or 43211, proven in a test environment.
    • Live Protect shield lp00031, a temporary mitigation described in Cisco’s Live Protect documentation, supported only on NX-OS 10.6(3) and, via a second shield package, on 10.6(3s) for the two Smart Switches; it’s unsupported on the Nexus 9804 and 9808 and needs SSH, Telnet, or NX-API access.

    IOS XR Hardening Release Reaches Every Version

    The IOS XR release assigns one CVE to each Common Weakness Enumeration (CWE) bucket of fixed bugs and scores it at the most severe defect in that bucket, per the rules in its risk-based disclosure FAQ.

    CVE-2026-20274, which covers memory-safety and resource-lifetime bugs, and CVE-2026-20279, which covers access-control bugs including missing authentication for critical functions and improper certificate validation, each carry a 9.8 ceiling in the record for CVE-2026-20274 and that for CVE-2026-20279.

    The remaining five, CVE-2026-20275 through 20278 and CVE-2026-20280, top out between 8.2 and 8.8.

    The vulnerabilities affect all releases regardless of device configuration, the IOS XR hardening advisory said.

    The XR7 (LNT) platforms, which include the Cisco 8000 Series, NCS 1010, NCS 540L, and NCS 5700 Series, have a dedicated SMU that applies across all releases.

    Cisco said there may be “approximately 16 SMUs available for each release,” that future releases 26.2.2 and 26.3.1 will be the first fixed releases needing no SMUs, and that customers running a release outside its table should open a Technical Assistance Center (TAC) case.

    SMUs are available for the following releases –

    • 6.9.2
    • 7.3.2
    • 7.9.2
    • 7.9.21
    • 7.10.2
    • 7.11.2
    • 7.11.21
    • 24.2.2
    • 24.2.21
    • 24.4.2
    • 25.2.21
    • 25.4.1
    • 25.4.2
    • 26.1.2
    • 26.2.1

    SMUs are listed as future releases for 24.1.2, 24.3.2, 25.1.2, and 25.2.2.

    The advisory lists the following SMU identifiers by functional area –

    • All XR7 (LNT) platforms – CSCwv19790, on all releases.
    • BGP – CSCwu14807; the 7.10 and earlier trains and 26.2.1 are not vulnerable.
    • crypto-ike – CSCwv19170.
    • gRPC – CSCwt41683.
    • IP-SLA – CSCwv19173.
    • IS-IS – CSCwv45645 and CSCwv19171; on 25.4.2, and on 25.4.1 for the NCS1001, NCS1004, and NCS1010, CSCwu13271 and CSCwv19171; 26.1.2 and 26.2.1 are not vulnerable.
    • MPLS and MPLS-TE – CSCwv40753 and CSCwu14825; on 24.2.21 for 64-bit ARM Cisco 8000 Series routers, CSCwv19181 and CSCwu14825.
    • Multicast – CSCwv19180 and CSCwu08799.
    • OSPF – CSCwv40741 and CSCwv19171; on 24.2.21 for 64-bit ARM Cisco 8000 Series routers, CSCwv19174 and CSCwv19171.
    • Segment routing, IPv6 only – CSCwu13268; CSCwv56312 on 7.11.21, 24.2.21, 25.2.21, and 25.4.1, on 7.9.21 for 64-bit ASR 9000 Series routers, and on 7.3.2 for the NCS1002; 26.1.2 and 26.2.1 are not vulnerable.
    • Segment routing, IPv4 only or IPv4 and IPv6 – CSCwv38342; on 24.2.21 for 64-bit ARM Cisco 8000 Series routers, CSCwv19178.
    • TCP Authentication Option – CSCwv36143; on 24.2.21 for 64-bit ARM Cisco 8000 Series routers, CSCwu14817; on 6.9.2 for 32-bit ASR 9000 Series routers, CSCww16661.
    • Zero Touch Provisioning (ZTP) – CSCwu36622; 26.2.1 is not vulnerable.

    CSCwv19171 applies to both IS-IS and OSPF, Cisco noted.

    The Hacker News cross-checked the seven CVE records against the advisory on September 3 and found that, of the 111 IOS XR releases Cisco lists as affected, 14 have SMUs available today, four are awaiting SMUs, and 93 must first be upgraded before a fix can be applied.

    Cybersecurity

    The September 2 drop is the third scheduled hardening release in 30 days, following the first hardening drop on August 5, which delivered the IOS XE hardening release and a Catalyst SD-WAN release, and two CVSS 10.0 releases for Crosswork and Secure Workload two weeks later.

    Separately, two publicly disclosed Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption flaws in Secure Email, CVE-2026-20354 and CVE-2026-20355 (CVSS scores: 5.9), allow a machine-in-the-middle attacker to recover plaintext from mail passing between gateways running AsyncOS 16.5.0 or earlier with S/MIME configured, Cisco said in the Secure Email advisory. Fixed releases for that pair are stated only in the bug records.

    The same day’s advisories also fixed a phone denial-of-service bug, CVE-2026-20281 (CVSS score: 7.5), in Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 devices registered to Unified Communications Manager with Web Access enabled, a setting that’s off by default. Fixes arrive in SIP Software 5.0(1), 14.4(1)SR3, 14.4(1)SR4, or 11.0(6)SR8 depending on the model.

    The development comes six days after Sygnia said the China-nexus threat actor Fire Ant, first documented in 2025, ran purpose-built implants on IOS XR routers that suppressed syslog delivery, filtered show command output, and supported a hidden Generic Routing Encapsulation (GRE) tunnel.

    The actor also captured packets from routers, uploaded them to external FTP servers, and made connection attempts and port scans against connected systems associated with critical infrastructure.

    The investigation began with a tunnel interface active on a router with no running configuration or commit history to explain it, which, Sygnia said in its Fire Ant report, suggested the device’s operational state “could no longer be trusted to match the configuration and audit records.”

    Sygnia did not identify how the actor first gained access to the routers or name any vulnerability.

    Attackers Cisco Code critical Flaw lets Nexus remote Root Run unauthenticated
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

    HPE patches critical ArubaOS-CX remote code execution flaw

    Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

    Microsoft: KB5120998 mouse reset bug affects only non-English PCs

    OpenAI confirms ChatGPT is down ahead of ‘Astra’ model launch

    HiddenLayer Raises $100 Million for AI Runtime Security

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Cybercab is Tesla’s ‘fork in the road’ moment 

    September 3, 2026

    Anthropic Released Claude Commerce Agents: An Apache-2.0 Blueprint for Shopping and Merchant Agents Across Retail, Travel, Telecom and Entertainment

    September 3, 2026

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    September 3, 2026

    Kraken And SoFi Link Crypto Trading To Banking Rails

    September 3, 2026
    Latest Posts

    Ultrafast X-rays capture chemistry unfolding atom by atom

    July 31, 2026

    How a PPE company’s highly publicized $32M Bitcoin strategy quietly expired without purchasing a single coin

    July 31, 2026

    Critical Flaw Led to Azure Cosmos DB Pwnage

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Cybercab is Tesla’s ‘fork in the road’ moment 

    September 3, 2026

    Anthropic Released Claude Commerce Agents: An Apache-2.0 Blueprint for Shopping and Merchant Agents Across Retail, Travel, Telecom and Entertainment

    September 3, 2026

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.