CRITICAL: Cisco Nexus 9000 CVE-2026-20212 Allows Unauthenticated Root RCE
Cisco patched CVE-2026-20212, a CVSS 9.8 flaw in Nexus 9000 Series switches built on Silicon One ASICs that lets an unauthenticated remote attacker execute code as root. The S1HAL process listens on TCP ports 43210 and 43211 through the default Layer 3 VRF, and NX-OS releases 10.3(1) through 10.6(3s) are affected. Upgrade to 10.6(4) or later, or apply an infrastructure access control list.